PT-2022-5874 · Zyxel · Zyxel Zywall+4
Alessandro Sgreccia
·
Published
2022-09-12
·
Updated
2022-12-08
·
CVE-2022-40603
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ZyXEL USG versions 4.30 through 4.72
ZyXEL ZyWALL versions 4.30 through 4.72
ZyXEL USG FLEX versions 4.50 through 5.31
ZyXEL VPN versions 4.30 through 5.31
ZyXEL ATP versions 4.32 through 5.31
Description
A cross-site scripting (XSS) issue in the CGI program of ZyXEL devices is related to the lack of protection of the web page structure. This could allow a remote attacker to trick a user into visiting a crafted URL with the XSS payload, potentially gaining access to some browser-based information if the malicious script is executed on the victim’s browser.
Recommendations
For ZyXEL USG versions 4.30 through 4.72, update to a version outside of this range to mitigate the risk.
For ZyXEL ZyWALL versions 4.30 through 4.72, update to a version outside of this range to mitigate the risk.
For ZyXEL USG FLEX versions 4.50 through 5.31, update to a version outside of this range to mitigate the risk.
For ZyXEL VPN versions 4.30 through 5.31, update to a version outside of this range to mitigate the risk.
For ZyXEL ATP versions 4.32 through 5.31, update to a version outside of this range to mitigate the risk.
As a temporary workaround, consider restricting access to the CGI program until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zyxel Atp
Zyxel Usg
Zyxel Usg Flex
Zyxel Vpn
Zyxel Zywall