|
209441
|
7.5 |
HIGH
Network
|
zyxel
|
cloudcnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated update_all_realm_license API.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-15341
|
2024-11-21 14:05 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209442
|
7.5 |
HIGH
Network
|
zyxel
|
cloudcnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded opt/axess/AXAssets/default_axess/axess/TR69/Handlers/turbolink/sshkeys/id_rsa SSH key.
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2020-15340
|
2024-11-21 14:05 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209443
|
6.1 |
MEDIUM
Network
|
zyxel
|
cloudcnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows live/CPEManager/AXCampaignManager/handle_campaign_script_link?script_name= XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15339
|
2024-11-21 14:05 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209444
|
5.3 |
MEDIUM
Network
|
zyxel
|
cloudcnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /cnr requests.
|
CWE-862
Missing Authorization
|
CVE-2020-15338
|
2024-11-21 14:05 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209445
|
5.3 |
MEDIUM
Network
|
zyxel
|
cloudcnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /registerCpe requests.
|
CWE-862
Missing Authorization
|
CVE-2020-15337
|
2024-11-21 14:05 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209446
|
5.3 |
MEDIUM
Network
|
zyxel
|
cloudcnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows escape-sequence injection into the /var/log/axxmpp.log file.
|
NVD-CWE-Other
|
CVE-2020-15334
|
2024-11-21 14:05 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209447
|
5.3 |
MEDIUM
Network
|
zyxel
|
cloudcnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows attackers to discover accounts via MySQL "select * from Administrator_users" and "select * from Users_users" requests.
|
CWE-89
SQL Injection
|
CVE-2020-15333
|
2024-11-21 14:05 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209448
|
9.8 |
CRITICAL
Network
|
zyxel
|
cloudcnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-15332
|
2024-11-21 14:05 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209449
|
9.8 |
CRITICAL
Network
|
zyxel
|
cloudcnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess.
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2020-15331
|
2024-11-21 14:05 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209450
|
5.3 |
MEDIUM
Network
|
zyxel
|
cloudcnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded APP_KEY in /opt/axess/etc/default/axess.
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2020-15330
|
2024-11-21 14:05 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|