CVE-2019-12581
27.06.2019, 15:15
A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows remote attackers to inject arbitrary web script or HTML via the err_msg parameter.
Vendor | Product | Version |
---|---|---|
zyxel | uag2100_firmware | 𝑥 ≤ 4.18\(aaiz.1\)c0 |
zyxel | uag4100_firmware | 𝑥 ≤ 4.18\(aatd.1\)c0 |
zyxel | uag5100_firmware | 𝑥 ≤ 4.18\(aapn.1\)c0 |
zyxel | usg110_firmware | 𝑥 ≤ 4.30 |
zyxel | usg210_firmware | 𝑥 ≤ 4.30 |
zyxel | usg310_firmware | 𝑥 ≤ 4.30 |
zyxel | usg1100_firmware | 𝑥 ≤ 4.30 |
zyxel | usg1900_firmware | 𝑥 ≤ 4.30 |
zyxel | usg2200-vpn_firmware | 𝑥 ≤ 4.30 |
𝑥
= Vulnerable software versions
References