Known vulnerabilities in WAC500H

Software: WAC500H
Software CPE: cpe:2.3:h:zyxel_communications_corp:wac500h:*:*:*:*:*:*:*:*
Total vulnerabilities: 13
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting WAC500H WAC500H is affected by 13 known vulnerabilities: 1 high, 3 medium, 9 low Critical High Medium Low

Vulnerabilities (13)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU140858 - Improper Authentication
CVE-2026-8508
CWE-287 Medium
No
No
- 04.08.2026 SB2026080427
#VU112893 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-6265
CWE-22 Low
No
No
6.70(ABWA.7) 15.07.2025 SB2025071523
#VU96715 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-7261
CWE-78 High
No
No
6.70(ABWA.5) 03.09.2024 SB2024090324
#VU94650 - Improper Privilege Management
CVE-2024-1575
CWE-269 Medium
No
No
6.70(ABWA.4) 23.07.2024 SB2024072302
#VU86621 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-6398
CWE-78 Low
No
No
6.70(ABWA.1) 20.02.2024 SB2024022031
#VU83523 - Improper Privilege Management
CVE-2023-5797
CWE-269 Low
No
No
- 28.11.2023 SB2023112820
#VU83518 - Improper Privilege Management
CVE-2023-37925
CWE-269 Low
No
No
- 28.11.2023 SB2023112820
#VU75467 - Exposure of sensitive information to an unauthorized actor
CVE-2023-22918
CWE-200 Medium
No
No
6.55(ABWA.0) 25.04.2023 SB2023042508
#VU63562 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-26532
CWE-78 Low
No
No
6.30(ABWA.3) 24.05.2022 SB2022052406
#VU63561 - Improper input validation
CVE-2022-26531
CWE-20 Low
Available
No
6.30(ABWA.3) 24.05.2022 SB2022052406
#VU53154 - Improper input validation
CVE-2020-24586
CWE-20 Low
No
No
- 12.05.2021 SB2021051211
SB2021051708
SB2021051810
and 34 more
#VU53098 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2020-24588
CWE-451 Low
No
No
- 11.05.2021 SB2021051118
SB2021051227
SB2021051708
and 57 more
#VU53096 -
CVE-2020-24587
Low
No
No
- 11.05.2021 SB2021051118
SB2021051708
SB2021051810
and 32 more