VYPR

MZK-DP300N

by Planex

CVEs (3)

  • CVE-2025-62777HigOct 28, 2025
    risk 0.57cvss 8.8epss 0.00

    Use of Hard-Coded Credentials issue exists in MZK-DP300N version 1.07 and earlier, which may allow an attacker within the local network to log in to the affected device via Telnet and execute arbitrary commands.

  • CVE-2024-45372MedSep 26, 2024
    risk 0.42cvss 6.5epss 0.00

    MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability. Viewing a malicious page while logging in to the web management page of the affected product may lead the user to perform unintended operations such as changing the login password,…

  • CVE-2025-21603MedJan 8, 2025
    risk 0.31cvss 4.8epss 0.00

    Cross-site scripting vulnerability exists in MZK-DP300N firmware versions 1.05 and earlier. If an attacker logs in to the affected product and manipulates the device settings, an arbitrary script may be executed on the logged-in user's web browser when accessing a crafted URL.