CVE-2023-27990
published 2023-04-24CVE-2023-27990: The cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG…
PriorityP421medium4.8CVSS 3.1
AVNACLPRHUIRSCCLILAN
EPSS
0.34%
26.7th percentile
The cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker with administrator privileges to store malicious scripts in a vulnerable device. A successful XSS attack could then result in the stored malicious scripts being executed when the user visits the Logs page of the GUI on the device.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | atp100_firmware | >= 4.32 < 5.36 | 5.36 |
| zyxel | atp100w_firmware | >= 4.32 < 5.36 | 5.36 |
| zyxel | atp200_firmware | >= 4.32 < 5.36 | 5.36 |
| zyxel | atp500_firmware | >= 4.32 < 5.36 | 5.36 |
| zyxel | atp700_firmware | >= 4.32 < 5.36 | 5.36 |
| zyxel | atp800_firmware | >= 4.32 < 5.36 | 5.36 |
| zyxel | atp_series_firmware | — | — |
| zyxel | usg20-vpn_firmware | >= 4.30 < 5.36 | 5.36 |
| zyxel | usg20_vpn_firmware | — | — |
| zyxel | usg_20w-vpn_firmware | >= 4.16 < 5.36 | 5.36 |
| zyxel | usg_flex_100_firmware | >= 4.50 < 5.36 | 5.36 |
| zyxel | usg_flex_100w_firmware | >= 4.50 < 5.36 | 5.36 |
| zyxel | usg_flex_200_firmware | >= 4.50 < 5.36 | 5.36 |
| zyxel | usg_flex_500_firmware | >= 4.50 < 5.36 | 5.36 |
| zyxel | usg_flex_50_firmware | — | — |
| zyxel | usg_flex_50_firmware | >= 4.50 < 5.36 | 5.36 |
| zyxel | usg_flex_50w_firmware | >= 4.16 < 5.36 | 5.36 |
| zyxel | usg_flex_700_firmware | >= 4.50 < 5.36 | 5.36 |
| zyxel | usg_flex_series_firmware | — | — |
| zyxel | vpn1000_firmware | >= 4.30 < 5.36 | 5.36 |
| zyxel | vpn100_firmware | >= 4.30 < 5.36 | 5.36 |
| zyxel | vpn300_firmware | >= 4.30 < 5.36 | 5.36 |
| zyxel | vpn50_firmware | >= 4.30 < 5.36 | 5.36 |
| zyxel | vpn_series_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-xss-vulnerability-and-post-authentication-command-injection-vulnerability-in-firewallshttps://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-xss-vulnerability-and-post-authentication-command-injection-vulnerability-in-firewalls
2023-04-24
Published