Zyxel Vpn Series Firmware vulnerabilities
37 known vulnerabilities affecting zyxel/vpn_series_firmware.
Total CVEs
37
CISA KEV
4
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL6HIGH17MEDIUM14
Vulnerabilities
Page 2 of 2
CVE-2023-34141P3HIGHCVSS 8.0v5.00 through 5.36 Patch 22023-07-17
CVE-2023-34141 [HIGH] CWE-78 CVE-2023-34141: A command injection vulnerability in the access point (AP) management feature of the Zyxel ATP serie
A command injection vulnerability in the access point (AP) management feature of the Zyxel ATP series firmware versions 5.00 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 5.00 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 5.00 through 5.36 Patch 2, VPN series fir
nvd
CVE-2023-22914P3HIGHCVSS 7.2v4.30 through 5.352023-04-24
CVE-2023-22914 [HIGH] CWE-22 CVE-2023-22914: A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmw
A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker with administrator privileges to execute unauthorized OS commands in the “tmp” directory by uploading a crafted file if
nvd
CVE-2023-22917P3HIGHCVSS 7.5v5.00 through 5.352023-04-24
CVE-2023-22917 [HIGH] CWE-120 CVE-2023-22917: A buffer overflow vulnerability in the “sdwan_iface_ipc” binary of Zyxel ATP series firmware version
A buffer overflow vulnerability in the “sdwan_iface_ipc” binary of Zyxel ATP series firmware versions 5.10 through 5.32, USG FLEX series firmware versions 5.00 through 5.32, USG FLEX 50(W) firmware versions 5.10 through 5.32, USG20(W)-VPN firmware versions 5.10 through 5.32, and VPN series firmware versions 5.00 through 5.35, which could allow a remot
nvd
CVE-2022-0910P3MEDIUMCVSS 6.5v4.32 through 5.212022-05-24
CVE-2022-0910 [MEDIUM] CWE-287 CVE-2022-0910: A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI pro
A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.32 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, and VPN series firmware versions 4.32 through 5.21, that could allow an authenticat
nvd
CVE-2023-22918P3MEDIUMCVSS 6.5v4.30 through 5.352023-04-24
CVE-2023-22918 [MEDIUM] CWE-359 CVE-2023-22918: A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firm
A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, VPN series firmware versions 4.30 through 5.35, NWA110AX firmwa
nvd
CVE-2022-2030P3MEDIUMCVSS 6.5v4.30 through 5.302022-07-19
CVE-2022-2030 [MEDIUM] CWE-22 CVE-2022-2030: A directory traversal vulnerability caused by specific character sequences within an improperly sani
A directory traversal vulnerability caused by specific character sequences within an improperly sanitized URL was identified in some CGI programs of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 firmware versions 4.50 through 5.30, USG FLEX 500 firmware versions 4.50 through 5.30, USG FLEX 700 firmware versions 4.50 through 5.
nvd
CVE-2022-0734P4MEDIUMCVSS 6.1v4.35 through 5.202022-05-24
CVE-2022-0734 [MEDIUM] CWE-79 CVE-2022-0734: A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series fi
A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.35 through 5.20, and VPN series firmware versions 4.35 through 5.20, that could allow an attacker to obtain some information stored in
nvd
CVE-2023-35139P4MEDIUMCVSS 6.1vversions 5.00 through 5.372023-11-28
CVE-2023-35139 [MEDIUM] CWE-79 CVE-2023-35139: A cross-site scripting (XSS) vulnerability in the CGI program of the Zyxel ATP series firmware versi
A cross-site scripting (XSS) vulnerability in the CGI program of the Zyxel ATP series firmware versions 5.10 through 5.37, USG FLEX series firmware versions 5.00 through 5.37, USG FLEX 50(W) series firmware versions 5.10 through 5.37, USG20(W)-VPN series firmware versions 5.10 through 5.37, and VPN series firmware versions 5.00 through 5.37, could al
nvd
CVE-2023-34140P4MEDIUMCVSS 6.5v4.30 through 5.36 Patch 22023-07-17
CVE-2023-34140 [MEDIUM] CWE-120 CVE-2023-34140: A buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.36 Patch 2,
A buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.36 Patch 2, USG FLEX series firmware versions 4.50 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 4.16 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 4.16 through 5.36 Patch 2, VPN series firmware versions 4.30 through 5.36 Patch 2, N
nvd
CVE-2022-40603P4MEDIUMCVSS 6.1v4.30 through 5.312022-12-06
CVE-2022-40603 [MEDIUM] CWE-79 CVE-2022-40603: A cross-site scripting (XSS) vulnerability in the CGI program of Zyxel ZyWALL/USG series firmware ve
A cross-site scripting (XSS) vulnerability in the CGI program of Zyxel ZyWALL/USG series firmware versions 4.30 through 4.72, VPN series firmware versions 4.30 through 5.31, USG FLEX series firmware versions 4.50 through 5.31, and ATP series firmware versions 4.32 through 5.31, which could allow an attacker to trick a user into visiting a crafted URL
nvd
CVE-2023-35136P4MEDIUMCVSS 5.5vversions 4.30 through 5.372023-11-28
CVE-2023-35136 [MEDIUM] CWE-20 CVE-2023-35136: An improper input validation vulnerability in the “Quagga” package of the Zyxel ATP series firmware
An improper input validation vulnerability in the “Quagga” package of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, and VPN series firmware versions 4.30 through 5.37, coul
nvd
CVE-2023-37925P4MEDIUMCVSS 5.5vversions 4.30 through 5.372023-11-28
CVE-2023-37925 [MEDIUM] CWE-269 CVE-2023-37925: An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firm
An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, VPN series firmware versions 4.30 through 5.37, N
nvd
CVE-2023-5797P4MEDIUMCVSS 5.5vversions 4.30 through 5.372023-11-28
CVE-2023-5797 [MEDIUM] CWE-269 CVE-2023-5797: An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firm
An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, VPN series firmware versions 4.30 through 5.37, NWA
nvd
CVE-2023-5960P4MEDIUMCVSS 5.5vversions 4.30 through 5.372023-11-28
CVE-2023-5960 [MEDIUM] CWE-269 CVE-2023-5960: An improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series f
An improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.37 and VPN series firmware versions 4.30 through 5.37 could allow an authenticated local attacker to access the system files on an affected device.
nvd
CVE-2023-5650P4MEDIUMCVSS 5.5vversions 4.30 through 5.372023-11-28
CVE-2023-5650 [MEDIUM] CWE-269 CVE-2023-5650: An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions
An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, and VPN series firmware versions 4.30 through 5.37, could allow
nvd
CVE-2023-37926P4MEDIUMCVSS 5.5vversions 4.30 through 5.372023-11-28
CVE-2023-37926 [MEDIUM] CWE-120 CVE-2023-37926: A buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLE
A buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, and VPN series firmware versions 4.30 through 5.37, could allow an authenticated local at
nvd
CVE-2023-27990P4MEDIUMCVSS 4.8v4.30 through 5.352023-04-24
CVE-2023-27990 [MEDIUM] CWE-79 CVE-2023-27990: The cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35
The cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker
nvd
← Previous2 / 2