CVE-2019-9955

On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
VendorProductVersion
zyxelatp200_firmware
4.31
zyxelatp500_firmware
4.31
zyxelatp800_firmware
4.31
zyxelusg20-vpn_firmware
4.31
zyxelusg20w-vpn_firmware
4.31
zyxelusg40_firmware
4.31
zyxelusg40w_firmware
4.31
zyxelusg60_firmware
4.31
zyxelusg60w_firmware
4.31
zyxelusg110_firmware
4.31
zyxelusg210_firmware
4.31
zyxelusg310_firmware
4.31
zyxelusg1100_firmware
4.31
zyxelusg1900_firmware
4.31
zyxelusg2200-vpn_firmware
4.31
zyxelzywall_110_firmware
4.31
zyxelzywall_310_firmware
4.31
zyxelzywall_1100_firmware
4.31
zyxelvpn50_firmware
-
zyxelvpn100_firmware
-
zyxelvpn300_firmware
-
𝑥
= Vulnerable software versions