On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter
Published Apr 22, 2019
6.1
MEDIUMCVSS 3.0
EPSS 21.18%
Description
On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter.
Affected products
No data.
Configuration 1
- 4.31
Configuration 2
- 4.31
Configuration 3
- 4.31
Configuration 4
- 4.31
Configuration 5
- 4.31
Running on/with
- n/a
Configuration 6
- 4.31
Configuration 7
- 4.31
Configuration 8
- 4.31
Configuration 9
- 4.31
Configuration 10
- 4.31
Configuration 11
- 4.31
Configuration 12
- 4.31
Configuration 13
- 4.31
Configuration 14
- 4.31
Configuration 15
- 4.31
Running on/with
- n/a
Configuration 16
- 4.31
Running on/with
- n/a
Configuration 17
- 4.31
Running on/with
- n/a
Configuration 18
- 4.31
Running on/with
- n/a
Configuration 19
- n/a
Configuration 20
- n/a
Configuration 21
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- http://packetstormsecurity.com/files/152525/Zyxel-ZyWall-Cross-Site-Scripting.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2019/Apr/22 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-19309 Advisory
- https://www.exploit-db.com/exploits/46706/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.securitymetrics.com/blog/Zyxel-Devices-Vulnerable-Cross-Site-Scripting-Login-page x_refsource_MISCPatchThird Party Advisory
- https://www.zyxel.com/support/reflected-cross-site-scripting-vulnerability-of-firewalls.shtml x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/152525/Zyxel-ZyWall-Cross-Site-Scripting.html | x_refsource_MISCExploitThird Party AdvisoryVDB Entry | |
| http://seclists.org/fulldisclosure/2019/Apr/22 | mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-19309 | Advisory | |
| https://www.exploit-db.com/exploits/46706/ | exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry | |
| https://www.securitymetrics.com/blog/Zyxel-Devices-Vulnerable-Cross-Site-Scripting-Login-page | x_refsource_MISCPatchThird Party Advisory | |
| https://www.zyxel.com/support/reflected-cross-site-scripting-vulnerability-of-firewalls.shtml | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.