Zyxel Nbg6604 Firmware vulnerabilities

4 known vulnerabilities affecting zyxel/nbg6604_firmware.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2023-33013HIGHCVSS 8.8v1.01\(abir.1\)c0vV1.01(ABIR.1)C02023-08-14
CVE-2023-33013 [HIGH] CWE-78 CVE-2023-33013: A post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware v A post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)C0 could allow an authenticated attacker to execute some OS commands remotely by sending a crafted HTTP request.
cvelistv5nvd
CVE-2023-22919HIGHCVSS 8.8v1.01\(abir.0\)c0vV1.01(ABIR.0)C02023-05-01
CVE-2023-22919 [HIGH] CWE-78 CVE-2023-22919: The post-authentication command injection vulnerability in the Zyxel NBG6604 firmware version V1.01( The post-authentication command injection vulnerability in the Zyxel NBG6604 firmware version V1.01(ABIR.0)C0 could allow an authenticated attacker to execute some OS commands remotely by sending a crafted HTTP request.
cvelistv5nvd
CVE-2021-35034CRITICALCVSS 9.1fixed in 1.00\(abir.9\)c02021-12-29
CVE-2021-35034 [HIGH] CWE-613 CVE-2021-35034: An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware co An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device if the correct token can be intercepted.
nvd
CVE-2021-35035MEDIUMCVSS 6.5fixed in 1.00\(abir.9\)c02021-12-29
CVE-2021-35035 [MEDIUM] CWE-312 CVE-2021-35035: A cleartext storage of sensitive information vulnerability in the Zyxel NBG6604 firmware could allow A cleartext storage of sensitive information vulnerability in the Zyxel NBG6604 firmware could allow a remote, authenticated attacker to obtain sensitive information from the configuration file.
nvd