CVE-2015-7256

UnknownEPSS 0.79%

Last modified

CVE-2015-7256 is a vulnerability of currently unknown severity. ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG1312-B10A, VMG1312-B30A, VMG1312-B30B, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, VMG8924-B30A, and VSG1435-B101 DSL CPEs; PMG5318-B20A GPONs; SBG3300-N000, SBG3300-NB00, and SBG3500-N000 small business gateways; GS1900-8 and GS1900-24 switches; and C1000Z, Q1000, FR1000Z, and P8702N project models use non-unique X.509 certificates and SSH host keys.. EPSS estimates a 0.79% chance of exploitation in the next 30 days.

Description

ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG1312-B10A, VMG1312-B30A, VMG1312-B30B, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, VMG8924-B30A, and VSG1435-B101 DSL CPEs; PMG5318-B20A GPONs; SBG3300-N000, SBG3300-NB00, and SBG3500-N000 small business gateways; GS1900-8 and GS1900-24 switches; and C1000Z, Q1000, FR1000Z, and P8702N project models use non-unique X.509 certificates and SSH host keys.

Metrics

EPSS Probability
0.79%

51.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
ZyxelNwa1100-N FirmwareAll versions
ZyxelNwa1100-Nh FirmwareAll versions
ZyxelNwa1121-Ni FirmwareAll versions
ZyxelNwa1123-Ac FirmwareAll versions
ZyxelNwa1123-Ni FirmwareAll versions
ZyxelP-660hn-51 FirmwareAll versions
ZyxelP-663hn-51 FirmwareAll versions
ZyxelVmg1312-B10a FirmwareAll versions
ZyxelVmg1312-B30a FirmwareAll versions
ZyxelVmg1312-B30b FirmwareAll versions
ZyxelVmg4380-B10a FirmwareAll versions
ZyxelVmg8324-B10a FirmwareAll versions
ZyxelVmg8924-B10a FirmwareAll versions
ZyxelVmg8924-B30a FirmwareAll versions
ZyxelVsg1435-B101 FirmwareAll versions
ZyxelPmg5318-B20a FirmwareAll versions
ZyxelSbg3300-N000 FirmwareAll versions
ZyxelSbg3300-Nb00 FirmwareAll versions
ZyxelSbg3500-N000 FirmwareAll versions
ZyxelGs1900-8 FirmwareAll versions
ZyxelGs1900-24 FirmwareAll versions
ZyxelC1000z FirmwareAll versions
ZyxelQ1000 FirmwareAll versions
ZyxelFr1000z FirmwareAll versions
ZyxelP8702n FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2015-7256?
ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG1312-B10A, VMG1312-B30A, VMG1312-B30B, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, VMG8924-B30A, and VSG1435-B101 DSL CPEs; PMG5318-B20A GPONs; SBG3300-N000, SBG3300-NB00, and SBG3500-N000 small business gateways; GS1900-8 and GS1900-24 switches; and C1000Z, Q1000, FR1000Z, and P8702N project models use non-unique X.509 certificates and SSH host keys.
How severe is CVE-2015-7256?
Severity scoring for CVE-2015-7256 is pending analysis. The EPSS model estimates a 0.79% probability of exploitation in the next 30 days.
How do I fix CVE-2015-7256?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2015-7256?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST