CVE Feed

    Dashboard / CVE / CVE-2022-0734

    CVE-2022-0734

    A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.35 through 5.20, and VPN series firmware versions 4.35 through 5.20, that could allow an attacker to obtain some information stored in the user's browser, such as cookies or session tokens, via a malicious script.

    Published:May 24, 2022
    Last Modified:Nov 21, 2024
    EPS:May 24, 2022
    EPSS Score:0.00326
    CVSS Score:5.8

    Affected Products

    Vendor
    Zyxel
    Product
    Atp100
    Vendor
    Zyxel
    Product
    Atp100 Firmware
    Vendor
    Zyxel
    Product
    Atp100w
    Vendor
    Zyxel
    Product
    Atp100w Firmware
    Vendor
    Zyxel
    Product
    Atp200
    Vendor
    Zyxel
    Product
    Atp200 Firmware
    Vendor
    Zyxel
    Product
    Atp500
    Vendor
    Zyxel
    Product
    Atp500 Firmware
    Vendor
    Zyxel
    Product
    Atp700
    Vendor
    Zyxel
    Product
    Atp700 Firmware
    Vendor
    Zyxel
    Product
    Atp800
    Vendor
    Zyxel
    Product
    Atp800 Firmware
    Vendor
    Zyxel
    Product
    Usg20
    Vendor
    Zyxel
    Product
    Usg200
    Vendor
    Zyxel
    Product
    Usg200 Firmware
    Vendor
    Zyxel
    Product
    Usg20 Firmware
    Vendor
    Zyxel
    Product
    Usg210
    Vendor
    Zyxel
    Product
    Usg210 Firmware
    Vendor
    Zyxel
    Product
    Usg2200
    Vendor
    Zyxel
    Product
    Usg2200 Firmware
    Vendor
    Zyxel
    Product
    Usg300
    Vendor
    Zyxel
    Product
    Usg300 Firmware
    Vendor
    Zyxel
    Product
    Usg310
    Vendor
    Zyxel
    Product
    Usg310 Firmware
    Vendor
    Zyxel
    Product
    Usg 110
    Vendor
    Zyxel
    Product
    Usg 1100
    Vendor
    Zyxel
    Product
    Usg 1100 Firmware
    Vendor
    Zyxel
    Product
    Usg 110 Firmware
    Vendor
    Zyxel
    Product
    Usg 1900
    Vendor
    Zyxel
    Product
    Usg 1900 Firmware
    Vendor
    Zyxel
    Product
    Usg 20w
    Vendor
    Zyxel
    Product
    Usg 20w-vpn
    Vendor
    Zyxel
    Product
    Usg 20w-vpn Firmware
    Vendor
    Zyxel
    Product
    Usg 20w Firmware
    Vendor
    Zyxel
    Product
    Usg 2200-vpn
    Vendor
    Zyxel
    Product
    Usg 2200-vpn Firmware
    Vendor
    Zyxel
    Product
    Usg 310
    Vendor
    Zyxel
    Product
    Usg 310 Firmware
    Vendor
    Zyxel
    Product
    Usg 40
    Vendor
    Zyxel
    Product
    Usg 40 Firmware
    Vendor
    Zyxel
    Product
    Usg 40w
    Vendor
    Zyxel
    Product
    Usg 40w Firmware
    Vendor
    Zyxel
    Product
    Usg 60
    Vendor
    Zyxel
    Product
    Usg 60 Firmware
    Vendor
    Zyxel
    Product
    Usg 60w
    Vendor
    Zyxel
    Product
    Usg 60w Firmware
    Vendor
    Zyxel
    Product
    Usg Flex 100
    Vendor
    Zyxel
    Product
    Usg Flex 100 Firmware
    Vendor
    Zyxel
    Product
    Usg Flex 100w
    Vendor
    Zyxel
    Product
    Usg Flex 100w Firmware
    Vendor
    Zyxel
    Product
    Usg Flex 200
    Vendor
    Zyxel
    Product
    Usg Flex 200 Firmware
    Vendor
    Zyxel
    Product
    Usg Flex 500
    Vendor
    Zyxel
    Product
    Usg Flex 500 Firmware
    Vendor
    Zyxel
    Product
    Usg Flex 700
    Vendor
    Zyxel
    Product
    Usg Flex 700 Firmware
    Vendor
    Zyxel
    Product
    Vpn100
    Vendor
    Zyxel
    Product
    Vpn1000
    Vendor
    Zyxel
    Product
    Vpn1000 Firmware
    Vendor
    Zyxel
    Product
    Vpn100 Firmware
    Vendor
    Zyxel
    Product
    Vpn300
    Vendor
    Zyxel
    Product
    Vpn300 Firmware
    Vendor
    Zyxel
    Product
    Vpn50
    Vendor
    Zyxel
    Product
    Vpn50 Firmware

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High