Zyxel Usg2200-vpn -

CPE Details

Zyxel Usg2200-vpn -
-
2019-10-24
15h01 +00:00
2019-10-24
15h01 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:h:zyxel:usg2200-vpn:-:*:*:*:*:*:*:*

Informations

Vendor

zyxel

Product

usg2200-vpn

Version

-

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-35029 2021-07-02 08h29 +00:00 An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.
9.8
Critical
CVE-2020-25014 2020-11-27 16h18 +00:00 A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted http packet.
9.8
Critical
CVE-2019-12581 2019-06-27 12h10 +00:00 A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows remote attackers to inject arbitrary web script or HTML via the err_msg parameter.
6.1
Medium
CVE-2019-12583 2019-06-27 12h01 +00:00 Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access or Denial of Service.
9.1
Critical
CVE-2019-9955 2019-04-22 17h38 +00:00 On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter.
6.1
Medium