📦 Vpn50 Firmware

by Zyxel

🔍 What is Vpn50 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-33009

CRITICAL CVSS 9.8 May 24, 2023

A buffer overflow vulnerability in Zyxel firewall notification functions allows unauthenticated attackers to cause denial-of-service or execute arbitrary code remotely. This affects multiple Zyxel fir...

CVE-2023-28771

CRITICAL CVSS 9.8 Apr 25, 2023

This vulnerability allows unauthenticated remote attackers to execute arbitrary operating system commands on affected Zyxel firewall devices by sending specially crafted IKE packets. It affects multip...

CVE-2022-0342

CRITICAL CVSS 9.8 Mar 28, 2022

This authentication bypass vulnerability in Zyxel firewall CGI programs allows attackers to circumvent web authentication and gain administrative access to affected devices. It affects multiple Zyxel ...

CVE-2020-29583

CRITICAL CVSS 9.8 Dec 22, 2020

CVE-2020-29583 is a critical vulnerability in Zyxel USG devices where firmware version 4.60 includes a hidden administrative account (zyfwp) with a hardcoded, unchangeable password found in cleartext....

CVE-2023-27991

HIGH CVSS 8.8 Apr 24, 2023

This is a post-authentication command injection vulnerability in Zyxel firewall CLI commands that allows authenticated attackers to execute arbitrary operating system commands remotely. It affects mul...

CVE-2023-22913

HIGH CVSS 8.1 Apr 24, 2023

A post-authentication command injection vulnerability in Zyxel USG FLEX and VPN series firewalls allows authenticated attackers to execute arbitrary commands through the account_operator.cgi program. ...

CVE-2023-22915

HIGH CVSS 7.5 Apr 24, 2023

A buffer overflow vulnerability in the fbwifi_forward.cgi CGI program of affected Zyxel devices allows remote unauthenticated attackers to cause denial-of-service conditions by sending crafted HTTP re...

CVE-2023-22917

HIGH CVSS 7.5 Apr 24, 2023

A buffer overflow vulnerability in Zyxel network devices allows remote unauthenticated attackers to cause denial of service by uploading a crafted configuration file. This affects multiple Zyxel firew...

CVE-2022-38547

HIGH CVSS 7.2 Feb 7, 2023

This is a post-authentication command injection vulnerability in Zyxel firewall devices that allows authenticated administrators to execute arbitrary operating system commands. It affects multiple Zyx...

CVE-2022-30526

HIGH CVSS 7.8 Jul 19, 2022

This CVE describes a local privilege escalation vulnerability in Zyxel firewall CLI commands where a local attacker can execute OS commands with root privileges in specific directories. It affects mul...

CVE-2022-26532

HIGH CVSS 7.8 May 24, 2022

This CVE-2022-26532 is an argument injection vulnerability in Zyxel network devices that allows local authenticated attackers to execute arbitrary OS commands via crafted arguments to the 'packet-trac...