Vulnerability Description
On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zyxel | Atp200 Firmware | 4.31 |
| Zyxel | Atp200 | - |
| Zyxel | Atp500 Firmware | 4.31 |
| Zyxel | Atp500 | - |
| Zyxel | Atp800 Firmware | 4.31 |
| Zyxel | Atp800 | - |
| Zyxel | Usg20-Vpn Firmware | 4.31 |
| Zyxel | Usg20-Vpn | - |
| Zyxel | Usg20W-Vpn Firmware | 4.31 |
| Zyxel | Usg20W-Vpn | - |
| Zyxel | Usg40 Firmware | 4.31 |
| Zyxel | Usg40 | - |
| Zyxel | Usg40W Firmware | 4.31 |
| Zyxel | Usg40W | - |
| Zyxel | Usg60 Firmware | 4.31 |
| Zyxel | Usg60 | - |
| Zyxel | Usg60W Firmware | 4.31 |
| Zyxel | Usg60W | - |
| Zyxel | Usg110 Firmware | 4.31 |
| Zyxel | Usg110 | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/152525/Zyxel-ZyWall-Cross-Site-Scripting.htExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2019/Apr/22Mailing ListThird Party Advisory
- https://www.exploit-db.com/exploits/46706/ExploitThird Party AdvisoryVDB Entry
- https://www.securitymetrics.com/blog/Zyxel-Devices-Vulnerable-Cross-Site-ScriptiPatchThird Party Advisory
- https://www.zyxel.com/support/reflected-cross-site-scripting-vulnerability-of-fiVendor Advisory
- http://packetstormsecurity.com/files/152525/Zyxel-ZyWall-Cross-Site-Scripting.htExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2019/Apr/22Mailing ListThird Party Advisory
- https://www.exploit-db.com/exploits/46706/ExploitThird Party AdvisoryVDB Entry
- https://www.securitymetrics.com/blog/Zyxel-Devices-Vulnerable-Cross-Site-ScriptiPatchThird Party Advisory
- https://www.zyxel.com/support/reflected-cross-site-scripting-vulnerability-of-fiVendor Advisory
FAQ
What is CVE-2019-9955?
CVE-2019-9955 is a vulnerability with a CVSS score of 6.1 (MEDIUM). On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security f...
How severe is CVE-2019-9955?
CVE-2019-9955 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-9955?
Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Atp200 Firmware, Zyxel Atp200, Zyxel Atp500 Firmware, Zyxel Atp500, Zyxel Atp800 Firmware.