Known vulnerabilities in USG FLEX 100W

Software: USG FLEX 100W
Software CPE: cpe:2.3:h:zyxel_communications_corp:usg_flex_100w:*:*:*:*:*:*:*:*
Total vulnerabilities: 6
Public exploits: 2
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting USG FLEX 100W USG FLEX 100W is affected by 6 known vulnerabilities: 1 high, 1 medium, 4 low Critical High Medium Low

Vulnerabilities (6)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU65413 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-2030
CWE-22 Medium
No
No
5.31 19.07.2022 SB2022071902
#VU65410 - Permissions, Privileges, and Access Controls
CVE-2022-30526
CWE-264 Low
Available
No
5.31 19.07.2022 SB2022071902
#VU63145 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-30525
CWE-78 High
Available
Exploited
5.30 13.05.2022 SB2022051308
#VU53154 - Improper input validation
CVE-2020-24586
CWE-20 Low
No
No
- 12.05.2021 SB2021051211
SB2021051708
SB2021051810
and 34 more
#VU53098 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2020-24588
CWE-451 Low
No
No
- 11.05.2021 SB2021051118
SB2021051227
SB2021051708
and 57 more
#VU53096 -
CVE-2020-24587
Low
No
No
- 11.05.2021 SB2021051118
SB2021051708
SB2021051810
and 32 more