Zyxel Nbg-418N V2 Firmware vulnerabilities

6 known vulnerabilities affecting zyxel/nbg-418n_v2_firmware.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2023-22921HIGHCVSS 7.5fixed in V1.00(AARP.14)C02023-05-01
CVE-2023-22921 [HIGH] CWE-79 CVE-2023-22921: A cross-site scripting (XSS) vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00 A cross-site scripting (XSS) vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote authenticated attacker with administrator privileges to store malicious scripts using a web management interface parameter, resulting in denial-of-service (DoS) conditions on an affected device.
cvelistv5nvd
CVE-2023-22922HIGHCVSS 7.5fixed in V1.00(AARP.14)C02023-05-01
CVE-2023-22922 [HIGH] CWE-120 CVE-2023-22922: A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote unauthenticated attacker to cause DoS conditions by sending crafted packets if Telnet is enabled on a vulnerable device.
cvelistv5nvd
CVE-2023-22923MEDIUMCVSS 6.5fixed in V1.00(AARP.14)C02023-05-01
CVE-2023-22923 [MEDIUM] CWE-134 CVE-2023-22923: A format string vulnerability in a binary of the Zyxel NBG-418N v2 firmware versions prior to V1.00( A format string vulnerability in a binary of the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote authenticated attacker to cause denial-of-service (DoS) conditions on an affected device.
cvelistv5nvd
CVE-2023-22924MEDIUMCVSS 4.9fixed in V1.00(AARP.14)C02023-05-01
CVE-2023-22924 [MEDIUM] CWE-120 CVE-2023-22924: A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote authenticated attacker with administrator privileges to cause denial-of-service (DoS) conditions by executing crafted CLI commands on a vulnerable device.
cvelistv5nvd
CVE-2022-45441MEDIUMCVSS 6.1fixed in V1.00(AARP.13)C02023-02-07
CVE-2022-45441 [MEDIUM] CWE-79 CVE-2022-45441: A cross-site scripting (XSS) vulnerability in Zyxel NBG-418N v2 firmware versions prior to V1.00(AAR A cross-site scripting (XSS) vulnerability in Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.13)C0, which could allow an attacker to store malicious scripts in the Logs page of the GUI on a vulnerable device. A successful XSS attack could force an authenticated user to execute the stored malicious scripts and then result in a denial-of-servi
cvelistv5nvd
CVE-2019-17354CRITICALCVSS 9.4v1.00\(aarp.9\)c02019-10-09
CVE-2019-17354 [CRITICAL] CWE-306 CVE-2019-17354: wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly wit wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify data fields of the page.
nvd