Showing 5 vulnerabilities on this page for Multiple Firewalls

Signals CISA KEV Ransomware Nuclei
Zyxel vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Zyxel Multiple Firewalls Path Traversal Vulnerability

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL.

CWE-22Nov 27, 2024
CVSS7.5v3.1EPSS3.02%PoCs0SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Zyxel Multiple Firewalls Buffer Overflow Vulnerability

A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.60 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) con

CWE-120May 24, 2023
CVSS9.8v3.1EPSS28.1%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Zyxel Multiple Firewalls Buffer Overflow Vulnerability

A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.25 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) co

CWE-120May 24, 2023
CVSS9.8v3.1EPSS28.8%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Zyxel Multiple Firewalls OS Command Injection Vulnerability

Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device.

CWE-78Apr 25, 2023
CVSS9.8v3.1EPSS99.3%PoCs4SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Zyxel Multiple Firewalls OS Command Injection Vulnerability

A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W) firmware versions 5.10 through 5.21 Patch 1, USG20(W)-VPN firmware versions 5.10 through 5.21 Patch 1, ATP series firmware versions 5.10 through 5.21 Patch 1, VPN series firmware versio

CWE-78May 12, 20221 related artifact
CVSS9.8v3.1EPSS>99.9%PoCs17SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX