Known vulnerabilities in USG20W-VPN

Software: USG20W-VPN
Software CPE: cpe:2.3:h:zyxel_communications_corp:usg20w-vpn:*:*:*:*:*:*:*:*
Total vulnerabilities: 42
Public exploits: 3
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting USG20W-VPN USG20W-VPN is affected by 42 known vulnerabilities: 2 critical, 4 high, 14 medium, 22 low Critical High Medium Low

Vulnerabilities (42)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU140855 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-14818
CWE-22 Low
No
No
5.43 04.08.2026 SB2026080420
#VU122411 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-11730
CWE-78 Low
No
No
5.42 05.02.2026 SB2026020583
#VU117407 - Missing Authorization
CVE-2025-9133
CWE-862 Medium
No
No
5.41 21.10.2025 SB2025102144
#VU117397 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-8078
CWE-78 Low
No
No
5.41 21.10.2025 SB2025102144
#VU101038 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-11667
CWE-22 Critical
No
Exploited
5.39 29.11.2024 SB2024112907
#VU96729 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-42061
CWE-79 Low
No
No
5.39 03.09.2024 SB2024090354
#VU96728 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-42060
CWE-78 Low
No
No
5.39 03.09.2024 SB2024090354
#VU96726 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-42059
CWE-78 Low
No
No
5.39 03.09.2024 SB2024090354
#VU96725 - NULL Pointer Dereference
CVE-2024-42058
CWE-476 Medium
No
No
5.39 03.09.2024 SB2024090354
#VU96722 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-42057
CWE-78 Critical
No
Exploited
5.39 03.09.2024 SB2024090354
#VU96720 - Memory corruption
CVE-2024-6343
CWE-119 Low
No
No
5.39 03.09.2024 SB2024090354
#VU86621 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-6398
CWE-78 Low
No
No
5.37 Patch 2 20.02.2024 SB2024022031
#VU86619 - Use of Externally-Controlled Format String
CVE-2023-6764
CWE-134 High
No
No
5.37 Patch 2 20.02.2024 SB2024022031
#VU86615 - Use of Externally-Controlled Format String
CVE-2023-6399
CWE-134 Low
No
No
5.37 Patch 2 20.02.2024 SB2024022031
#VU83523 - Improper Privilege Management
CVE-2023-5797
CWE-269 Low
No
No
5.37 Patch 1 28.11.2023 SB2023112820
#VU83522 - Improper Privilege Management
CVE-2023-5650
CWE-269 Low
No
No
5.37 Patch 1 28.11.2023 SB2023112820
#VU83521 - Integer overflow
CVE-2023-4398
CWE-190 Medium
No
No
5.37 Patch 1 28.11.2023 SB2023112820
#VU83520 - Memory corruption
CVE-2023-4397
CWE-119 Low
No
No
5.37 Patch 1 28.11.2023 SB2023112820
#VU83518 - Improper Privilege Management
CVE-2023-37925
CWE-269 Low
No
No
5.37 Patch 1 28.11.2023 SB2023112820
#VU83517 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-35139
CWE-79 Low
No
No
5.37 Patch 1 28.11.2023 SB2023112820


Showing elements 1 - 20 out of 42