CVE-2022-40603
MEDIUMZyxel Firewalls and VPN Devices 4.30-5.31 - Cross-Site Scripting via CGI Program
Title source: llmDescription
A cross-site scripting (XSS) vulnerability in the CGI program of Zyxel ZyWALL/USG series firmware versions 4.30 through 4.72, VPN series firmware versions 4.30 through 5.31, USG FLEX series firmware versions 4.50 through 5.31, and ATP series firmware versions 4.32 through 5.31, which could allow an attacker to trick a user into visiting a crafted URL with the XSS payload. Then, the attacker could gain access to some browser-based information if the malicious script is executed on the victim’s browser.
References (1)
Core 1
Core References
Scores
CVSS v3
4.7
EPSS
0.0067
EPSS Percentile
71.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (19)
zyxel/atp100_firmware
4.32 - 5.31
zyxel/atp100w_firmware
4.32 - 5.31
zyxel/atp200_firmware
4.32 - 5.31
zyxel/atp500_firmware
4.32 - 5.31
zyxel/atp700_firmware
4.32 - 5.31
zyxel/atp800_firmware
4.32 - 5.31
zyxel/usg40_firmware
4.30 - 4.72
zyxel/usg40w_firmware
4.30 - 4.72
zyxel/usg60_firmware
4.30 - 4.72
zyxel/usg60w_firmware
4.30 - 4.72
... and 9 more
Published
Dec 06, 2022
Tracked Since
Feb 18, 2026