← All CVEs

CVE-2019-9955

medium · 6.1

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter.

6.1
CVSS
21.2%
EPSS (exploit prob.)
97th
EPSS percentile
2019-04-22
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses

CWE-79

Affected products

VendorProductAffected versions
zyxelatp200_firmware4.31
zyxelatp200all versions
zyxelatp500_firmware4.31
zyxelatp500all versions
zyxelatp800_firmware4.31
zyxelatp800all versions
zyxelusg20-vpn_firmware4.31
zyxelusg20-vpnall versions
zyxelusg20w-vpn_firmware4.31
zyxelusg20w-vpnall versions
zyxelusg40_firmware4.31
zyxelusg40all versions
zyxelusg40w_firmware4.31
zyxelusg40wall versions
zyxelusg60_firmware4.31
zyxelusg60all versions
zyxelusg60w_firmware4.31
zyxelusg60wall versions
zyxelusg110_firmware4.31
zyxelusg110all versions
zyxelusg210_firmware4.31
zyxelusg210all versions
zyxelusg310_firmware4.31
zyxelusg310all versions
zyxelusg1100_firmware4.31
zyxelusg1100all versions
zyxelusg1900_firmware4.31
zyxelusg1900all versions
zyxelusg2200-vpn_firmware4.31
zyxelusg2200-vpnall versions
zyxelzywall_110_firmware4.31
zyxelzywall_110all versions
zyxelzywall_310_firmware4.31
zyxelzywall_310all versions
zyxelzywall_1100_firmware4.31
zyxelzywall_1100all versions
zyxelvpn50_firmwareall versions
zyxelvpn50all versions
zyxelvpn100_firmwareall versions
zyxelvpn100all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-9955