Zyxel Vulnerabilities and Affected Products
Vulnerabilities associated with NBG-418N v2 firmware.
Products
Clear product- USG FLEX series firmware51 vulnerabilities
- ATP series firmware49 vulnerabilities
- VPN series firmware37 vulnerabilities
- USG FLEX 50(W) series firmware28 vulnerabilities
- USG20(W)-VPN series firmware28 vulnerabilities
- NAS326 firmware15 vulnerabilities
- NAS542 firmware14 vulnerabilities
- USG FLEX 50(W) firmware11 vulnerabilities
- nas326_firmware9 vulnerabilities
- nas542_firmware9 vulnerabilities
- usg_flex_50w_firmware9 vulnerabilities
- USG/ZyWALL series firmware8 vulnerabilities
- USG20(W)-VPN firmware8 vulnerabilities
- VMG8825-T50K firmware8 vulnerabilities
- VMG3625-T50B firmware7 vulnerabilities
- WAC500 firmware7 vulnerabilities
- atp800_firmware6 vulnerabilities
- usg_flex_700h_firmware6 vulnerabilities
- Multiple Firewalls5 vulnerabilities
- NBG-418N v2 firmware5 vulnerabilities
- NR7101 firmware5 vulnerabilities
- NWA50AX firmware5 vulnerabilities
- usg_flex_firmware5 vulnerabilities
- WBE660S firmware5 vulnerabilities
- ZyWALL/USG series firmware5 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-22922HIGH | A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote unauthenticated attacker to cause DoS conditions by sending crafted packets if Telnet is enabled on a vulnerable device. CWE-120May 1, 2023 | CVSS7.5v3.1 | EPSS0.933% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-22924MEDIUM | A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote authenticated attacker with administrator privileges to cause denial-of-service (DoS) conditions by executing crafted CLI commands on a vulnerable device. CWE-120May 1, 2023 | CVSS4.9v3.1 | EPSS0.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-22923MEDIUM | A format string vulnerability in a binary of the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote authenticated attacker to cause denial-of-service (DoS) conditions on an affected device. CWE-134May 1, 2023 | CVSS6.5v3.1 | EPSS0.788% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-22921HIGH | A cross-site scripting (XSS) vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote authenticated attacker with administrator privileges to store malicious scripts using a web management interface parameter, resulting in denial-of-service (DoS) conditions on an affected device. CWE-79May 1, 2023 | CVSS7.5v3.1 | EPSS0.502% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-45441MEDIUM | A cross-site scripting (XSS) vulnerability in Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.13)C0, which could allow an attacker to store malicious scripts in the Logs page of the GUI on a vulnerable device. A successful XSS attack could force an authenticated user to execute the stored malicious scripts and then result in a denial-of-service (DoS) condition when the user visits the Logs page of the GUI on the device. CWE-79Feb 7, 2023 | CVSS6.1v3.1 | EPSS0.353% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |