cbcvebase.
CVE-2019-9955
published 2019-04-22

CVE-2019-9955: On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL…

medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EXPLOIT
On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter.

Affected

18 ranges
VendorProductVersion rangeFixed in
zyxelatp200_firmware
zyxelatp500_firmware
zyxelatp800_firmware
zyxelusg1100_firmware
zyxelusg110_firmware
zyxelusg1900_firmware
zyxelusg20-vpn_firmware
zyxelusg20w-vpn_firmware
zyxelusg210_firmware
zyxelusg2200-vpn_firmware
zyxelusg310_firmware
zyxelusg40_firmware
zyxelusg40w_firmware
zyxelusg60_firmware
zyxelusg60w_firmware
zyxelzywall_1100_firmware
zyxelzywall_110_firmware
zyxelzywall_310_firmware