Page 3 of 35 results (0.045 seconds)

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 1

26 Jun 2020 — Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded opt/axess/AXAssets/default_axess/axess/TR69/Handlers/turbolink/sshkeys/id_rsa SSH key. Zyxel CloudCNM SecuManager versiones 3.1.0 y 3.1.1, presenta una clave SSH embebida en opt/axess/AXAssets/default_axess/axess/TR69/Handlers/turbolink/sshkeys/id_rsa • https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html • CWE-311: Missing Encryption of Sensitive Data •

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 1

26 Jun 2020 — Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated update_all_realm_license API. Zyxel CloudCNM SecuManager versiones 3.1.0 y 3.1.1, presenta una API update_all_realm_license no autenticada • https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html • CWE-522: Insufficiently Protected Credentials •

CVSS: 5.3EPSS: 0%CPEs: 2EXPL: 2

26 Jun 2020 — Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user API. Zyxel CloudCNM SecuManager versiones 3.1.0 y 3.1.1, presenta una API zy_install_user no autenticada • https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html • CWE-311: Missing Encryption of Sensitive Data •

CVSS: 5.3EPSS: 0%CPEs: 2EXPL: 1

26 Jun 2020 — Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user_key API. Zyxel CloudCNM SecuManager versiones 3.1.0 y 3.1.1, presenta una API zy_install_user_key no autenticada • https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html • CWE-311: Missing Encryption of Sensitive Data •

CVSS: 5.3EPSS: 0%CPEs: 2EXPL: 1

26 Jun 2020 — Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_user_id_and_key API. Zyxel CloudCNM SecuManager versiones 3.1.0 y 3.1.1, presenta una API zy_get_user_id_and_key no autenticada • https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html • CWE-311: Missing Encryption of Sensitive Data •

CVSS: 5.3EPSS: 0%CPEs: 2EXPL: 1

26 Jun 2020 — Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_instances_for_update API. Zyxel CloudCNM SecuManager versiones 3.1.0 y 3.1.1, presenta una API zy_get_instances_for_update no autenticada • https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html • CWE-311: Missing Encryption of Sensitive Data •

CVSS: 5.3EPSS: 0%CPEs: 2EXPL: 1

26 Jun 2020 — Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a /live/GLOBALS API with the CLOUDCNM key. Zyxel CloudCNM SecuManager versiones 3.1.0 y 3.1.1, presenta una API /live/GLOBALS con la clave CLOUDCNM • https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html • CWE-311: Missing Encryption of Sensitive Data •

CVSS: 10.0EPSS: 0%CPEs: 2EXPL: 1

26 Jun 2020 — Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account. Zyxel CloudCNM SecuManager versiones 3.1.0 y 3.1.1, presenta una contraseña q6xV4aW8bQ4cfD-b para la cuenta axiros • https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html • CWE-522: Insufficiently Protected Credentials •

CVSS: 5.3EPSS: 0%CPEs: 2EXPL: 1

26 Jun 2020 — Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded Erlang cookie for ejabberd replication. Zyxel CloudCNM SecuManager versiones 3.1.0 y 3.1.1, presenta una cookie Erlang embebida para la replicación de ejabberd • https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html • CWE-312: Cleartext Storage of Sensitive Information •

CVSS: 5.3EPSS: 0%CPEs: 2EXPL: 1

26 Jun 2020 — Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded certificate for Ejabberd in ejabberd.pem. Zyxel CloudCNM SecuManager versiones 3.1.0 y 3.1.1, presenta un certificado embebido para Ejabberd en el archivo ejabberd.pem • https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html • CWE-798: Use of Hard-coded Credentials •