2 results (0.048 seconds)

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 1

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a world-readable axess/opt/axXMPPHandler/config/xmpp_config.py file that stores hardcoded credentials. Zyxel CloudCNM SecuManager versiones 3.1.0 y 3.1.1, presenta un archivo axess/opt/axXMPPHandler/config/xmpp_config.py de tipo world-readable que almacena credenciales embebidas • https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html https://www.zyxel.com/support/vulnerabilities-of-CloudCNM-SecuManager.shtml • CWE-798: Use of Hard-coded Credentials •

CVSS: 10.0EPSS: 5%CPEs: 2EXPL: 1

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows use of live/CPEManager/AXCampaignManager/delete_cpes_by_ids?cpe_ids= for eval injection of Python code. Zyxel CloudCNM SecuManager versiones 3.1.0 y 3.1.1, permite el uso de live/CPEManager/AXCampaignManager/delete_cpes_by_ids?cpe_ids= para una inyección eval del código Python • https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html https://www.zyxel.com/support/vulnerabilities-of-CloudCNM-SecuManager.shtml • CWE-94: Improper Control of Generation of Code ('Code Injection') •