6.1

CVE-2019-12581

Exploit

A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows remote attackers to inject arbitrary web script or HTML via the err_msg parameter.

Data is provided by the National Vulnerability Database (NVD)
ZyxelUag2100 Firmware Version <= 4.18\(aaiz.1\)c0
   ZyxelUag2100 Version-
ZyxelUag4100 Firmware Version <= 4.18\(aatd.1\)c0
   ZyxelUag4100 Version-
ZyxelUag5100 Firmware Version <= 4.18\(aapn.1\)c0
   ZyxelUag5100 Version-
ZyxelUsg110 Firmware Version <= 4.30
   ZyxelUsg110 Version-
ZyxelUsg210 Firmware Version <= 4.30
   ZyxelUsg210 Version-
ZyxelUsg310 Firmware Version <= 4.30
   ZyxelUsg310 Version-
ZyxelUsg1100 Firmware Version <= 4.30
   ZyxelUsg1100 Version-
ZyxelUsg1900 Firmware Version <= 4.30
   ZyxelUsg1900 Version-
ZyxelUsg2200-vpn Firmware Version <= 4.30
   ZyxelUsg2200-vpn Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 55.65% 0.98
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.