CVE-2019-12581
published 2019-06-27CVE-2019-12581: A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows remote…
PriorityP341medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EXPLOIT
EPSS
6.40%
92.9th percentile
A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows remote attackers to inject arbitrary web script or HTML via the err_msg parameter.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | uag2100_firmware | <= 4.18\(aaiz.1\)c0 | — |
| zyxel | uag4100_firmware | <= 4.18\(aatd.1\)c0 | — |
| zyxel | uag5100_firmware | <= 4.18\(aapn.1\)c0 | — |
| zyxel | usg1100_firmware | <= 4.30 | — |
| zyxel | usg110_firmware | <= 4.30 | — |
| zyxel | usg1900_firmware | <= 4.30 | — |
| zyxel | usg210_firmware | <= 4.30 | — |
| zyxel | usg2200-vpn_firmware | <= 4.30 | — |
| zyxel | usg310_firmware | <= 4.30 | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Nuclei
Zyxel ZyWal/USG/UAG Devices - Cross-Site Scripting
nuclei·CVSS 6.1
CVE-2019-12581 [MEDIUM] Zyxel ZyWal/USG/UAG Devices - Cross-Site Scripting
Zyxel ZyWal/USG/UAG Devices - Cross-Site Scripting
Zyxel ZyWall, USG, and UAG devices allow remote attackers to inject arbitrary web script or HTML via the err_msg parameter free_time_failed.cgi CGI program, aka reflective cross-site scripting.
Template:
id: CVE-2019-12581
info:
name: Zyxel ZyWal/USG/UAG Devices - Cross-Site Scripting
author: n-thumann
severity: medium
description: Zyxel ZyWall, USG, and UAG devices allow remote attackers to inject arbitrary web script or HTML via the err_msg parameter free_time_failed.cgi CGI program, aka reflective cross-site scripting.
impact: |
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the victim's browser, leading to session hijacking, defacement, or theft of sensitive
https://n-thumann.de/blog/zyxel-gateways-missing-access-control-in-account-generator-xss/https://sec-consult.com/en/blog/advisories/reflected-cross-site-scripting-in-zxel-zywall/index.htmlhttps://www.zyxel.com/support/vulnerabilities-related-to-the-Free-Time-feature.shtmlhttps://www.zyxel.com/us/en/https://n-thumann.de/blog/zyxel-gateways-missing-access-control-in-account-generator-xss/https://sec-consult.com/en/blog/advisories/reflected-cross-site-scripting-in-zxel-zywall/index.htmlhttps://www.zyxel.com/support/vulnerabilities-related-to-the-Free-Time-feature.shtmlhttps://www.zyxel.com/us/en/
2019-06-27
Published