VulnerabilityModified
CVE-2021-46387
ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS).
MEDIUM 6.1EPSS 21.0%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 21.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads to bypass security restriction to achieve Cross Site Scripting, which allows an attacker able to execute arbitrary JavaScript codes to perform multiple attacks such as clipboard hijacking and session hijacking.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 20.95% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- zyxel/zywall 2 plus internet security appliance firmware
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/166189/Zyxel-ZyWALL-2-Plus-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- https://drive.google.com/drive/folders/1_XfWBLqxT2Mqt7uB663Sjlc62pE8-rcN?usp=sharingExploit, Third Party Advisory
- https://www.zyxel.com/uk/en/products_services/zywall_2_plus.shtmlBroken Link, Vendor Advisory
- https://www.zyxel.com/us/en/support/security_advisories.shtmlVendor Advisory
- http://packetstormsecurity.com/files/166189/Zyxel-ZyWALL-2-Plus-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- https://drive.google.com/drive/folders/1_XfWBLqxT2Mqt7uB663Sjlc62pE8-rcN?usp=sharingExploit, Third Party Advisory
- https://www.zyxel.com/uk/en/products_services/zywall_2_plus.shtmlBroken Link, Vendor Advisory
- https://www.zyxel.com/us/en/support/security_advisories.shtmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.