Zyxel · Zyxel Xgs2210-52Hp · CVE-2019-13495
Name of the Vulnerable Software and Affected Versions:
Zyxel XGS2210-52HP version 4.50
Description:
The issue allows remote authenticated users to inject arbitrary web script via an `rpSys.html` `Name` or `Location` field, due to multiple stored cross-site scripting (XSS) issues.
Recommendations:
For Zyxel XGS2210-52HP version 4.50, consider disabling access to the `rpSys.html` page until a patch is available, and restrict the use of the `Name` and `Location` fields to minimize the risk of exploitation.