CVE-2019-12581
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
27/06/2019
Last modified:
28/06/2019
Description
A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows remote attackers to inject arbitrary web script or HTML via the err_msg parameter.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:zyxel:uag2100_firmware:*:*:*:*:*:*:*:* | 4.18\(aaiz.1\)c0 (including) | |
| cpe:2.3:h:zyxel:uag2100:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:uag4100_firmware:*:*:*:*:*:*:*:* | 4.18\(aatd.1\)c0 (including) | |
| cpe:2.3:h:zyxel:uag4100:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:uag5100_firmware:*:*:*:*:*:*:*:* | 4.18\(aapn.1\)c0 (including) | |
| cpe:2.3:h:zyxel:uag5100:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:usg110_firmware:*:*:*:*:*:*:*:* | 4.30 (including) | |
| cpe:2.3:h:zyxel:usg110:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:usg210_firmware:*:*:*:*:*:*:*:* | 4.30 (including) | |
| cpe:2.3:h:zyxel:usg210:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:usg310_firmware:*:*:*:*:*:*:*:* | 4.30 (including) | |
| cpe:2.3:h:zyxel:usg310:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:usg1100_firmware:*:*:*:*:*:*:*:* | 4.30 (including) | |
| cpe:2.3:h:zyxel:usg1100:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:usg1900_firmware:*:*:*:*:*:*:*:* | 4.30 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://n-thumann.de/blog/zyxel-gateways-missing-access-control-in-account-generator-xss/
- https://sec-consult.com/en/blog/advisories/reflected-cross-site-scripting-in-zxel-zywall/index.html
- https://www.zyxel.com/support/vulnerabilities-related-to-the-Free-Time-feature.shtml
- https://www.zyxel.com/us/en/



