CVE-2019-12583
published 2019-06-27CVE-2019-12583: Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by…
PriorityP272critical9.1CVSS 3.0
AVNACLPRNUINSUCNIHAH
EXPLOIT
EPSS
43.93%
98.6th percentile
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access or Denial of Service.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | uag2100_firmware | <= 4.18\(aaiz.1\)c0 | — |
| zyxel | uag4100_firmware | <= 4.18\(aatd.1\)c0 | — |
| zyxel | uag5100_firmware | <= 4.18\(aapn.1\)c0 | — |
| zyxel | usg1100_firmware | <= 4.33\(aapk.0\)c0 | — |
| zyxel | usg110_firmware | <= 4.33\(aaph.0\)c0 | — |
| zyxel | usg1900_firmware | <= 4.33\(aapl.0\)c0 | — |
| zyxel | usg210_firmware | <= 4.33\(aapi.0\)c0 | — |
| zyxel | usg2200-vpn_firmware | <= 4.33\(abae.0\)c0 | — |
| zyxel | usg310_firmware | <= 4.33\(aapj.0\)c0 | — |
| zyxel | zywall_1100_firmware | <= 4.33\(aaac.0\)c0 | — |
| zyxel | zywall_110_firmware | <= 4.33\(aaaa.0\)c0 | — |
| zyxel | zywall_310_firmware | <= 4.33\(aaab.0\)c0 | — |
| zyxel | zywall_vpn100_firmware | <= 10.02\(abfv.0\)c0 | — |
| zyxel | zywall_vpn300_firmware | <= 10.02\(abfc.0\)c0 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect unauthenticated GET requests to /free_time.cgi; a 200 response containing both 'free_time_redirect.cgi?u=' and '&smsOnly=0' in the body confirms the vulnerable account-generator endpoint is publicly accessible. ↗
- →Shodan/FOFA/Google dork for exposed Zyxel ZyWall admin interfaces: search for HTTP title 'zywall' to identify potentially vulnerable internet-facing devices. ↗
- ·The vulnerability affects multiple Zyxel product lines (UAG, USG, ZyWall); the CPE in the template targets UAG2100 firmware specifically, but scope is broader. ↗
- ·The 'Free Time' guest-account generator endpoint (/free_time.cgi) requires no authentication; exploitation requires only network reachability to the management interface. ↗
CVSS provenance
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Nuclei
Zyxel ZyWall UAG/USG - Account Creation Access
nuclei·CVSS 9.1
CVE-2019-12583 [CRITICAL] Zyxel ZyWall UAG/USG - Account Creation Access
Zyxel ZyWall UAG/USG - Account Creation Access
Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator via the "Free Time" component. This can lead to unauthorized network access or DoS attacks.
Template:
id: CVE-2019-12583
info:
name: Zyxel ZyWall UAG/USG - Account Creation Access
author: n-thumann,daffainfo
severity: critical
description: Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator via the "Free Time" component. This can lead to unauthorized network access or DoS attacks.
impact: |
An attacker can exploit this vulnerability to create unauthorized accounts with administrative privileges.
remediation: |
Apply the latest firmwa
No writeups or analysis indexed.
https://n-thumann.de/blog/zyxel-gateways-missing-access-control-in-account-generator-xss/https://www.zyxel.com/support/vulnerabilities-related-to-the-Free-Time-feature.shtmlhttps://n-thumann.de/blog/zyxel-gateways-missing-access-control-in-account-generator-xss/https://www.zyxel.com/support/vulnerabilities-related-to-the-Free-Time-feature.shtml
2019-06-27
Published