CVE-2019-12583
critical · 9.1A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access or Denial of Service.
9.1
CVSS
43.9%
EPSS (exploit prob.)
99th
EPSS percentile
2019-06-27
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Weaknesses
CWE-425
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| zyxel | uag2100_firmware | <= 4.18\(aaiz.1\)c0 |
| zyxel | uag2100 | all versions |
| zyxel | uag4100_firmware | <= 4.18\(aatd.1\)c0 |
| zyxel | uag4100 | all versions |
| zyxel | uag5100_firmware | <= 4.18\(aapn.1\)c0 |
| zyxel | uag5100 | all versions |
| zyxel | usg110_firmware | <= 4.33\(aaph.0\)c0 |
| zyxel | usg110 | all versions |
| zyxel | usg210_firmware | <= 4.33\(aapi.0\)c0 |
| zyxel | usg210 | all versions |
| zyxel | usg310_firmware | <= 4.33\(aapj.0\)c0 |
| zyxel | usg310 | all versions |
| zyxel | usg1100_firmware | <= 4.33\(aapk.0\)c0 |
| zyxel | usg1100 | all versions |
| zyxel | usg1900_firmware | <= 4.33\(aapl.0\)c0 |
| zyxel | usg1900 | all versions |
| zyxel | usg2200-vpn_firmware | <= 4.33\(abae.0\)c0 |
| zyxel | usg2200-vpn | all versions |
| zyxel | zywall_vpn100_firmware | <= 10.02\(abfv.0\)c0 |
| zyxel | zywall_vpn100 | all versions |
| zyxel | zywall_vpn300_firmware | <= 10.02\(abfc.0\)c0 |
| zyxel | zywall_vpn300 | all versions |
| zyxel | zywall_110_firmware | <= 4.33\(aaaa.0\)c0 |
| zyxel | zywall_110 | all versions |
| zyxel | zywall_310_firmware | <= 4.33\(aaab.0\)c0 |
| zyxel | zywall_310 | all versions |
| zyxel | zywall_1100_firmware | <= 4.33\(aaac.0\)c0 |
| zyxel | zywall_1100 | all versions |
Check a specific version with /api/v1/cve/match.
References
- https://n-thumann.de/blog/zyxel-gateways-missing-access-control-in-account-generator-xss/
- https://www.zyxel.com/support/vulnerabilities-related-to-the-Free-Time-feature.shtml
- https://n-thumann.de/blog/zyxel-gateways-missing-access-control-in-account-generator-xss/
- https://www.zyxel.com/support/vulnerabilities-related-to-the-Free-Time-feature.shtml
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-12583