CVE-2019-12581
A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows remote attackers to inject arbitrary web script or HTML via the err_msg parameter.
Published:Jun 27, 2019
Last Modified:Nov 21, 2024
EPS:Jun 27, 2019
EPSS Score:0.55651
CVSS Score:6.1
Affected Products
Vendor
Product
Action
Vendor
Zyxel
Product
Uag2100
Zyxel
Uag2100
Vendor
Zyxel
Product
Uag2100 Firmware
Zyxel
Uag2100 Firmware
Vendor
Zyxel
Product
Uag4100
Zyxel
Uag4100
Vendor
Zyxel
Product
Uag4100 Firmware
Zyxel
Uag4100 Firmware
Vendor
Zyxel
Product
Uag5100
Zyxel
Uag5100
Vendor
Zyxel
Product
Uag5100 Firmware
Zyxel
Uag5100 Firmware
Vendor
Zyxel
Product
Usg110
Zyxel
Usg110
Vendor
Zyxel
Product
Usg1100
Zyxel
Usg1100
Vendor
Zyxel
Product
Usg1100 Firmware
Zyxel
Usg1100 Firmware
Vendor
Zyxel
Product
Usg110 Firmware
Zyxel
Usg110 Firmware
Vendor
Zyxel
Product
Usg1900
Zyxel
Usg1900
Vendor
Zyxel
Product
Usg1900 Firmware
Zyxel
Usg1900 Firmware
Vendor
Zyxel
Product
Usg210
Zyxel
Usg210
Vendor
Zyxel
Product
Usg210 Firmware
Zyxel
Usg210 Firmware
Vendor
Zyxel
Product
Usg2200-vpn
Zyxel
Usg2200-vpn
Vendor
Zyxel
Product
Usg2200-vpn Firmware
Zyxel
Usg2200-vpn Firmware
Vendor
Zyxel
Product
Usg310
Zyxel
Usg310
Vendor
Zyxel
Product
Usg310 Firmware
Zyxel
Usg310 Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
