📦 Usg 20w Vpn Firmware

by Zyxel

🔍 What is Usg 20w Vpn Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-33009

CRITICAL CVSS 9.8 May 24, 2023

A buffer overflow vulnerability in Zyxel firewall notification functions allows unauthenticated attackers to cause denial-of-service or execute arbitrary code remotely. This affects multiple Zyxel fir...

CVE-2023-33012

HIGH CVSS 8.8 Jul 17, 2023

An unauthenticated LAN-based attacker can execute arbitrary OS commands on affected Zyxel network devices by sending a malicious GRE configuration when cloud management is enabled. This affects multip...

CVE-2023-34141

HIGH CVSS 8.0 Jul 17, 2023

This CVE describes a command injection vulnerability in Zyxel firewall and WLAN controller products that allows LAN-based attackers to execute arbitrary OS commands. Attackers must first trick an auth...

CVE-2023-28767

HIGH CVSS 8.8 Jul 17, 2023

This vulnerability allows an unauthenticated attacker on the local network to inject OS commands into the configuration data of affected Zyxel devices when cloud management is enabled. It affects mult...

CVE-2023-27991

HIGH CVSS 8.8 Apr 24, 2023

This is a post-authentication command injection vulnerability in Zyxel firewall CLI commands that allows authenticated attackers to execute arbitrary operating system commands remotely. It affects mul...

CVE-2023-22915

HIGH CVSS 7.5 Apr 24, 2023

A buffer overflow vulnerability in the fbwifi_forward.cgi CGI program of affected Zyxel devices allows remote unauthenticated attackers to cause denial-of-service conditions by sending crafted HTTP re...

CVE-2023-22917

HIGH CVSS 7.5 Apr 24, 2023

A buffer overflow vulnerability in Zyxel network devices allows remote unauthenticated attackers to cause denial of service by uploading a crafted configuration file. This affects multiple Zyxel firew...

CVE-2022-26532

HIGH CVSS 7.8 May 24, 2022

This CVE-2022-26532 is an argument injection vulnerability in Zyxel network devices that allows local authenticated attackers to execute arbitrary OS commands via crafted arguments to the 'packet-trac...