Known vulnerabilities in USG FLEX 100W
Vendor:
ZyXEL Communications Corp.
Software:
USG FLEX 100W
Software CPE:
cpe:2.3:h:zyxel_communications_corp:usg_flex_100w:*:*:*:*:*:*:*:*
Website:
https://www.zyxel.com/
Total vulnerabilities:
6
Public exploits:
2
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU65413 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2022-2030 |
CWE-22 | Medium | 5.31 | 19.07.2022 |
SB2022071902 |
||
| #VU65410 - Permissions, Privileges, and Access Controls CVE-2022-30526 |
CWE-264 | Low | 5.31 | 19.07.2022 |
SB2022071902 |
||
| #VU63145 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2022-30525 |
CWE-78 | High | 5.30 | 13.05.2022 |
SB2022051308 |
||
| #VU53154 - Improper input validation CVE-2020-24586 |
CWE-20 | Low | - | 12.05.2021 |
SB2021051211 SB2021051708 SB2021051810 and 34 more |
||
| #VU53098 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing) CVE-2020-24588 |
CWE-451 | Low | - | 11.05.2021 |
SB2021051118 SB2021051227 SB2021051708 and 57 more |
||
| #VU53096 - CVE-2020-24587 |
Low | - | 11.05.2021 |
SB2021051118 SB2021051708 SB2021051810 and 32 more |