CVE-2019-9955
Zyxel ZyWall 310 / ZyWall 110 / USG1900 / ATP500 / USG40 - Login Page Cross-Site Scripting
Record summary
CVE-2019-9955 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter.
Exploitation context
Proofs of concept
1Catalogued exploits
ExploitDBZyxel ZyWall 310 / ZyWall 110 / USG1900 / ATP500 / USG40 - Login Page Cross-Site ScriptingExploitDB exploitby Aaron BishopNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMZyxel - Cross-Site ScriptingCVSS 6.1
Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, and ZyWALL 1100 devices contain a reflected cross-site scripting vulnerability on the security firewall login page via the mp_idx parameter.
Impact
Attackers can execute scripts in the victim's browser, potentially stealing cookies, session tokens, or performing actions on behalf of the user.
Remediation
Apply the latest firmware updates provided by Zyxel to fix the reflected cross-site scripting vulnerability.
Source: ProjectDiscovery