cbcvebase.
CVE-2019-12583
published 2019-06-27

CVE-2019-12583: Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by…

PriorityP272critical9.1CVSS 3.0
AVNACLPRNUINSUCNIHAH
EXPLOIT
EPSS
43.93%
98.6th percentile
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access or Denial of Service.

Affected

14 ranges
VendorProductVersion rangeFixed in
zyxeluag2100_firmware<= 4.18\(aaiz.1\)c0
zyxeluag4100_firmware<= 4.18\(aatd.1\)c0
zyxeluag5100_firmware<= 4.18\(aapn.1\)c0
zyxelusg1100_firmware<= 4.33\(aapk.0\)c0
zyxelusg110_firmware<= 4.33\(aaph.0\)c0
zyxelusg1900_firmware<= 4.33\(aapl.0\)c0
zyxelusg210_firmware<= 4.33\(aapi.0\)c0
zyxelusg2200-vpn_firmware<= 4.33\(abae.0\)c0
zyxelusg310_firmware<= 4.33\(aapj.0\)c0
zyxelzywall_1100_firmware<= 4.33\(aaac.0\)c0
zyxelzywall_110_firmware<= 4.33\(aaaa.0\)c0
zyxelzywall_310_firmware<= 4.33\(aaab.0\)c0
zyxelzywall_vpn100_firmware<= 10.02\(abfv.0\)c0
zyxelzywall_vpn300_firmware<= 10.02\(abfc.0\)c0

Detection & IOCsextracted from sources · hover to see the quote

path/free_time.cgi
otherfree_time_redirect.cgi?u=
other&smsOnly=0
  • Detect unauthenticated GET requests to /free_time.cgi; a 200 response containing both 'free_time_redirect.cgi?u=' and '&smsOnly=0' in the body confirms the vulnerable account-generator endpoint is publicly accessible.
  • Shodan/FOFA/Google dork for exposed Zyxel ZyWall admin interfaces: search for HTTP title 'zywall' to identify potentially vulnerable internet-facing devices.
  • ·The vulnerability affects multiple Zyxel product lines (UAG, USG, ZyWall); the CPE in the template targets UAG2100 firmware specifically, but scope is broader.
  • ·The 'Free Time' guest-account generator endpoint (/free_time.cgi) requires no authentication; exploitation requires only network reachability to the management interface.

CVSS provenance

nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.