peter bassill · operator
$ cve CVE-2019-12583 JSON

CVE-2019-12583

9.1
CRITICAL · CVSS 3.0 · EPSS 43.9% (pctl 99)

Patch early

EPSS 43.9% — above the 10% action threshold.

Description

Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access or Denial of Service.

Scoring

CVSS9.1 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS43.93% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-425
On CISA KEVno
Public exploitnone known
Published2019-06-27
Last modified2026-06-17

Affected (28)

VendorProduct
zyxeluag2100
zyxeluag2100 firmware
zyxeluag4100
zyxeluag4100 firmware
zyxeluag5100
zyxeluag5100 firmware
zyxelusg110
zyxelusg110 firmware
zyxelusg1100
zyxelusg1100 firmware
zyxelusg1900
zyxelusg1900 firmware
zyxelusg210
zyxelusg210 firmware
zyxelusg2200-vpn
zyxelusg2200-vpn firmware
zyxelusg310
zyxelusg310 firmware
zyxelzywall 110
zyxelzywall 110 firmware
zyxelzywall 1100
zyxelzywall 1100 firmware
zyxelzywall 310
zyxelzywall 310 firmware
zyxelzywall vpn100
zyxelzywall vpn100 firmware
zyxelzywall vpn300
zyxelzywall vpn300 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD