CVE-2022-45441

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
07/02/2023
Last modified:
06/12/2024

Description

A cross-site scripting (XSS) vulnerability in Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.13)C0, which could allow an attacker to store malicious scripts in the Logs page of the GUI on a vulnerable device. A successful XSS attack could force an authenticated user to execute the stored malicious scripts and then result in a denial-of-service (DoS) condition when the user visits the Logs page of the GUI on the device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:zyxel:nbg-418n_firmware:*:*:*:*:*:*:*:* 1.00\(aarp.10\)c0 (including)
cpe:2.3:h:zyxel:nbg-418n:v2:*:*:*:*:*:*:*