Filtered by vendor Zyxel Subscriptions
Total 276 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2020-15337 1 Zyxel 1 Cloudcnm Secumanager 2024-08-04 5.3 Medium
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /registerCpe requests.
CVE-2020-15342 1 Zyxel 1 Cloudcnm Secumanager 2024-08-04 5.3 Medium
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user API.
CVE-2020-15343 1 Zyxel 1 Cloudcnm Secumanager 2024-08-04 5.3 Medium
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user_key API.
CVE-2020-15318 1 Zyxel 1 Cloudcnm Secumanager 2024-08-04 5.9 Medium
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/mysql chroot directory tree.
CVE-2020-15331 1 Zyxel 1 Cloudcnm Secumanager 2024-08-04 9.8 Critical
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess.
CVE-2020-15325 1 Zyxel 1 Cloudcnm Secumanager 2024-08-04 5.3 Medium
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded Erlang cookie for ejabberd replication.
CVE-2020-15346 1 Zyxel 1 Cloudcnm Secumanager 2024-08-04 5.3 Medium
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a /live/GLOBALS API with the CLOUDCNM key.
CVE-2020-15315 1 Zyxel 1 Cloudcnm Secumanager 2024-08-04 5.9 Medium
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/axess chroot directory tree.
CVE-2020-15313 1 Zyxel 1 Cloudcnm Secumanager 2024-08-04 5.9 Medium
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account.
CVE-2020-15339 1 Zyxel 1 Cloudcnm Secumanager 2024-08-04 6.1 Medium
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows live/CPEManager/AXCampaignManager/handle_campaign_script_link?script_name= XSS.
CVE-2020-15323 1 Zyxel 1 Cloudcnm Secumanager 2024-08-04 9.8 Critical
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the cloud1234 password for the a1@chopin account default credentials.
CVE-2020-15312 1 Zyxel 1 Cloudcnm Secumanager 2024-08-04 5.9 Medium
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account.
CVE-2020-15322 1 Zyxel 1 Cloudcnm Secumanager 2024-08-04 9.8 Critical
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account.
CVE-2020-15317 1 Zyxel 1 Cloudcnm Secumanager 2024-08-04 5.9 Medium
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/axess chroot directory tree.
CVE-2020-15319 1 Zyxel 1 Cloudcnm Secumanager 2024-08-04 5.9 Medium
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/mysql chroot directory tree.
CVE-2020-15347 1 Zyxel 1 Cloudcnm Secumanager 2024-08-04 9.8 Critical
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account.
CVE-2020-15326 1 Zyxel 1 Cloudcnm Secumanager 2024-08-04 5.3 Medium
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded certificate for Ejabberd in ejabberd.pem.
CVE-2020-15327 1 Zyxel 1 Cloudcnm Secumanager 2024-08-04 7.5 High
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication.
CVE-2020-15329 1 Zyxel 1 Cloudcnm Secumanager 2024-08-04 5.3 Medium
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak Data.fs permissions.
CVE-2020-15324 1 Zyxel 1 Cloud Cnm Secumanager 2024-08-04 9.8 Critical
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a world-readable axess/opt/axXMPPHandler/config/xmpp_config.py file that stores hardcoded credentials.