Zyxel Vulnerabilities and Affected Products
Vulnerabilities associated with usg_flex_700h_firmware.
Products
Clear product- USG FLEX series firmware51 vulnerabilities
- ATP series firmware49 vulnerabilities
- VPN series firmware37 vulnerabilities
- USG FLEX 50(W) series firmware28 vulnerabilities
- USG20(W)-VPN series firmware28 vulnerabilities
- NAS326 firmware15 vulnerabilities
- NAS542 firmware14 vulnerabilities
- USG FLEX 50(W) firmware11 vulnerabilities
- nas326_firmware9 vulnerabilities
- nas542_firmware9 vulnerabilities
- usg_flex_50w_firmware9 vulnerabilities
- USG/ZyWALL series firmware8 vulnerabilities
- USG20(W)-VPN firmware8 vulnerabilities
- VMG8825-T50K firmware8 vulnerabilities
- VMG3625-T50B firmware7 vulnerabilities
- WAC500 firmware7 vulnerabilities
- atp800_firmware6 vulnerabilities
- usg_flex_700h_firmware6 vulnerabilities
- Multiple Firewalls5 vulnerabilities
- NBG-418N v2 firmware5 vulnerabilities
- NR7101 firmware5 vulnerabilities
- NWA50AX firmware5 vulnerabilities
- usg_flex_firmware5 vulnerabilities
- WBE660S firmware5 vulnerabilities
- ZyWALL/USG series firmware5 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-9677MEDIUM | The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions could allow an authenticated local attacker to gain privilege escalation by stealing the authentication token of a login administrator. Note that this attack could be successful only if the administrator has not logged out. CWE-522Oct 22, 2024 | CVSS5.5v3.1 | EPSS0.153% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-42060HIGH | A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and USG20(W)-VPN series firmware versions from V4.16 through V5.38 could allow an authenticated attacker with administrator privileges to execute some OS commands on an affected device by uploading a crafted internal user agreement file to the vulnerable d… CWE-78Sep 3, 2024 | CVSS7.2v3.1 | EPSS1.34% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-42059HIGH | A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX series firmware versions from V5.00 through V5.38, USG FLEX 50(W) series firmware versions from V5.00 through V5.38, and USG20(W)-VPN series firmware versions from V5.00 through V5.38 could allow an authenticated attacker with administrator privileges to execute some OS commands on an affected device by uploading a crafted compressed language file via FTP. CWE-78Sep 3, 2024 | CVSS7.2v3.1 | EPSS1.34% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-42058HIGH | A null pointer dereference vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V5.20 through V5.38, and USG20(W)-VPN series firmware versions from V5.20 through V5.38 could allow an unauthenticated attacker to cause DoS conditions by sending crafted packets to a vulnerable device. CWE-476Sep 3, 2024 | CVSS7.5v3.1 | EPSS0.621% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-42057HIGH | Zyxel zld Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and USG20(W)-VPN series firmware versions from V4.16 through V5.38 could allow an unauthenticated attacker to execute some OS commands on an affected device by sending a crafted username to the vulnerable device. Note that this attack could be success… CWE-78Sep 3, 2024 | CVSS8.1v3.1 | EPSS1.32% | PoCs0 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2024-7203HIGH | A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firmware versions from V4.60 through V5.38 could allow an authenticated attacker with administrator privileges to execute some operating system (OS) commands on an affected device by executing a crafted CLI command. CWE-78Sep 3, 2024 | CVSS7.2v3.1 | EPSS1.34% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |