← Vulnerability feed

Vulnerability record · CVE-2015-7256 · published 28 September 2017

CVE-2015-7256: Zyxel nwa1100-n firmware vulnerability

Zyxel · Nwa1100 N Firmware

ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG1312-B10A, VMG1312-B30A, VMG1312-B30B, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, VMG8924-B30A, and VSG1435-B101 DSL CPEs; PMG5318-B20A GPONs; SBG3300-N000, SBG3300-NB00, and SBG3500-N000 small business gateways; GS1900-8 and GS1900-24 switches; and C1000Z, Q1000, FR1000Z, and P8702N project models use non-unique X.509 certificates and SSH host keys.

5.9 CVSS 3.0 Medium EPSS 0.79% · top 45.4% CWE-310 · CWE-310
5.9CVSS 3.0 base score, v2 4.3
0.79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
25Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG1312-B10A, VMG1312-B30A, VMG1312-B30B, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, VMG8924-B30A, and VSG1435-B101 DSL CPEs; PMG5318-B20A GPONs; SBG3300-N000, SBG3300-NB00, and SBG3500-N000 small business gateways; GS1900-8 and GS1900-24 switches; and C1000Z, Q1000, FR1000Z, and P8702N project models use non-unique X.509 certificates and SSH host keys.

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

25 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-7256 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-7273Zyxel gs1900-8 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-base…KEVEPSS 2.5%9.8CVE-2019-15800Zyxel gs1900-8 firmware os command injection vulnerabilityAn issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in the cmd_sys_traceroute_exec()…EPSS 3.9%9.1CVE-2019-15803Zyxel gs1900-8 firmware improper authentication vulnerabilityAn issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Through an undocumented sequence of keypresses, undocumented fun…EPSS 1.3%8.8CVE-2019-15799Zyxel gs1900-8 firmware improper privilege management vulnerabilityAn issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. User accounts created through the web interface of the device, w…EPSS 2.3%8.0CVE-2021-35031Zyxel gs1900-8 firmware os command injection vulnerabilityA vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authen…EPSS 0.46%7.8CVE-2021-35032Zyxel gs1900-8 firmware os command injection vulnerabilityA vulnerability in the 'libsal.so' of the Zyxel GS1900 series firmware version 2.60 could allow an authenticated local user to execute arbitrary OS c…EPSS 0.21%7.5CVE-2026-7287Zyxel nwa1100-n firmware classic buffer overflow vulnerability** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), formUpgradeCert(), and formDelcert…EPSS 0.55%7.5CVE-2019-15801Zyxel gs1900-8 firmware hard-coded credentials vulnerabilityAn issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware image contains encrypted passwords that are used to…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2015-7256), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.