Zyxel Pmg5318-B20A Firmware vulnerabilities
4 known vulnerabilities affecting zyxel/pmg5318-b20a_firmware.
Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2
Vulnerabilities
Page 1 of 1
CVE-2015-6016CRITICALCVSS 9.8vv100aanc0b52015-12-31
CVE-2015-6016 [CRITICAL] CWE-255 CVE-2015-6016: ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0), PMG5318-B20A devices with firmware 1.00A
ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0), PMG5318-B20A devices with firmware 1.00AANC0b5, and NBG-418N devices have a default password of 1234 for the admin account, which allows remote attackers to obtain administrative access via unspecified vectors.
nvd
CVE-2015-6018CRITICALCVSS 9.8PoC≤ v100aanc0b52015-12-31
CVE-2015-6018 [CRITICAL] CWE-264 CVE-2015-6018: The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0
The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary commands via the PingIPAddr parameter.
nvd
CVE-2015-6019HIGHCVSS 8.5vv100aanc0b52015-12-31
CVE-2015-6019 [HIGH] CVE-2015-6019: The management portal on ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 does not terminate ses
The management portal on ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 does not terminate sessions upon a logout action, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.
nvd
CVE-2015-6020HIGHCVSS 8.0vv100aanc0b52015-12-31
CVE-2015-6020 [HIGH] CWE-264 CVE-2015-6020: ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 allow remote authenticated users to obtain admi
ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 allow remote authenticated users to obtain administrative privileges by leveraging access to the user account.
nvd