CVE-2022-40603
A cross-site scripting (XSS) vulnerability in the CGI program of Zyxel ZyWALL/USG series firmware versions 4.30 through 4.72, VPN series firmware versions 4.30 through 5.31, USG FLEX series firmware versions 4.50 through 5.31, and ATP series firmware…
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
A cross-site scripting (XSS) vulnerability in the CGI program of Zyxel ZyWALL/USG series firmware versions 4.30 through 4.72, VPN series firmware versions 4.30 through 5.31, USG FLEX series firmware versions 4.50 through 5.31, and ATP series firmware versions 4.32 through 5.31, which could allow an attacker to trick a user into visiting a crafted URL with the XSS payload. Then, the attacker could gain access to some browser-based information if the malicious script is executed on the victim’s browser.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.36% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- zyxel/atp800 firmware · zyxel/atp700 firmware · zyxel/atp500 firmware · zyxel/atp200 firmware · zyxel/atp100 firmware · zyxel/atp100w firmware · zyxel/usg flex 100w firmware · zyxel/usg flex 200 firmware · zyxel/usg flex 500 firmware · zyxel/usg flex 700 firmware · zyxel/usg flex 50w firmware · zyxel/vpn1000 firmware · zyxel/vpn300 firmware · zyxel/vpn100 firmware · zyxel/vpn50 firmware · zyxel/usg40 firmware · zyxel/usg40w firmware · zyxel/usg60 firmware · zyxel/usg60w firmware
- Source
- security@zyxel.com.tw
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.