Vulnerability Description
A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows remote attackers to inject arbitrary web script or HTML via the err_msg parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zyxel | Uag2100 Firmware | <= 4.18\(aaiz.1\)c0 |
| Zyxel | Uag2100 | - |
| Zyxel | Uag4100 Firmware | <= 4.18\(aatd.1\)c0 |
| Zyxel | Uag4100 | - |
| Zyxel | Uag5100 Firmware | <= 4.18\(aapn.1\)c0 |
| Zyxel | Uag5100 | - |
| Zyxel | Usg110 Firmware | <= 4.30 |
| Zyxel | Usg110 | - |
| Zyxel | Usg210 Firmware | <= 4.30 |
| Zyxel | Usg210 | - |
| Zyxel | Usg310 Firmware | <= 4.30 |
| Zyxel | Usg310 | - |
| Zyxel | Usg1100 Firmware | <= 4.30 |
| Zyxel | Usg1100 | - |
| Zyxel | Usg1900 Firmware | <= 4.30 |
| Zyxel | Usg1900 | - |
| Zyxel | Usg2200-Vpn Firmware | <= 4.30 |
| Zyxel | Usg2200-Vpn | - |
Related Weaknesses (CWE)
References
- https://n-thumann.de/blog/zyxel-gateways-missing-access-control-in-account-generExploitThird Party Advisory
- https://sec-consult.com/en/blog/advisories/reflected-cross-site-scripting-in-zxeExploitPatchThird Party Advisory
- https://www.zyxel.com/support/vulnerabilities-related-to-the-Free-Time-feature.sPatchVendor Advisory
- https://www.zyxel.com/us/en/Vendor Advisory
- https://n-thumann.de/blog/zyxel-gateways-missing-access-control-in-account-generExploitThird Party Advisory
- https://sec-consult.com/en/blog/advisories/reflected-cross-site-scripting-in-zxeExploitPatchThird Party Advisory
- https://www.zyxel.com/support/vulnerabilities-related-to-the-Free-Time-feature.sPatchVendor Advisory
- https://www.zyxel.com/us/en/Vendor Advisory
FAQ
What is CVE-2019-12581?
CVE-2019-12581 is a vulnerability with a CVSS score of 6.1 (MEDIUM). A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows remote attackers to inject arbitrary web script or H...
How severe is CVE-2019-12581?
CVE-2019-12581 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12581?
Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Uag2100 Firmware, Zyxel Uag2100, Zyxel Uag4100 Firmware, Zyxel Uag4100, Zyxel Uag5100 Firmware.