CVE-2019-12581
Zyxel ZyWal/USG/UAG Devices - Cross-Site Scripting
Record summary
CVE-2019-12581 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows remote attackers to inject arbitrary web script or HTML via the err_msg parameter.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMZyxel ZyWal/USG/UAG Devices - Cross-Site ScriptingCVSS 6.1
Zyxel ZyWall, USG, and UAG devices allow remote attackers to inject arbitrary web script or HTML via the err_msg parameter free_time_failed.cgi CGI program, aka reflective cross-site scripting.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Apply the latest firmware update provided by Zyxel to fix the XSS vulnerability.
Source: ProjectDiscovery