CVE-2015-7256: Medium severity zyxel nwa1100-nh firmware vulnerability

Published Sep 27, 2017
·
Updated

ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG1312-B10A, VMG1312-B30A, VMG1312-B30B, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, VMG8924-B30A, and VSG1435-B101 DSL CPEs; PMG5318-B20A GPONs; SBG3300-N000, SBG3300-NB00, and SBG3500-N000 small business gateways; GS1900-8 and GS1900-24 switches; and C1000Z, Q1000, FR1000Z, and P8702N project models use non-unique X.509 certificates and SSH host keys.

Affected Software

50 affected components
Zyxel Nwa1100-n Firmware
Zyxel NWA1100-N
Zyxel Nwa1100-nh Firmware
Zyxel NWA1100-NH
Zyxel Nwa1121-ni Firmware
Zyxel NWA1121-NI
Zyxel Nwa1123-ac Firmware
Zyxel NWA1123-AC
Zyxel Nwa1123-ni Firmware
Zyxel NWA1123-NI
Zyxel P-660hn-51 Firmware
Zyxel P-660HN-51
Zyxel P-663hn-51 Firmware
Zyxel P-663HN-51
Zyxel Vmg1312-b10a Firmware
Zyxel VMG1312-B10A
Zyxel Vmg1312-b30a Firmware
Zyxel VMG1312-B30A
Zyxel Vmg1312-b30b Firmware
Zyxel VMG1312-B30B
Zyxel Vmg4380-b10a Firmware
Zyxel VMG4380-B10A
Zyxel Vmg8324-b10a Firmware
Zyxel VMG8324-B10A
Zyxel Vmg8924-b10a Firmware
Zyxel VMG8924-B10A
Zyxel Vmg8924-b30a Firmware
Zyxel VMG8924-B30A
Zyxel Vsg1435-b101 Firmware
Zyxel VSG1435-B101
Zyxel Pmg5318-b20a Firmware
Zyxel PMG5318-B20A
Zyxel Sbg3300-n000 Firmware
Zyxel SBG3300-N000
Zyxel Sbg3300-nb00 Firmware
Zyxel SBG3300-NB00
Zyxel Sbg3500-n000 Firmware
Zyxel SBG3500-N000
Zyxel GS1900-8 firmware
Zyxel GS1900-8
Zyxel Gs1900-24 Firmware
Zyxel GS1900-24
Zyxel C1000z Firmware
Zyxel C1000Z
Zyxel Q1000 Firmware
Zyxel Q1000
Zyxel Fr1000z Firmware
Zyxel FR1000Z
Zyxel P8702n Firmware
Zyxel P8702N

Event History

Sep 27, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2015-7256?

CVE-2015-7256 has been assigned a Medium severity rating due to its potential for unauthorized access.

2

How do I fix CVE-2015-7256?

To mitigate CVE-2015-7256, update your ZyXEL firmware to the latest version provided by the manufacturer.

3

What devices are affected by CVE-2015-7256?

CVE-2015-7256 affects various ZyXEL access points and DSL CPEs including models like NWA1100-N and VMG1312 series.

4

Is CVE-2015-7256 remotely exploitable?

Yes, CVE-2015-7256 can be exploited remotely, making it critical to secure affected devices.

5

What types of vulnerabilities does CVE-2015-7256 involve?

CVE-2015-7256 involves vulnerabilities related to insufficient protection of SSH private keys and certificates.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203