peter bassill · operator
$ cve CVE-2019-9955 JSON

CVE-2019-9955 EXPLOIT

6.1
MEDIUM · CVSS 3.0 · EPSS 21.2% (pctl 98)

Patch early

A public exploit exists.

Description

On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter.

Scoring

CVSS6.1 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS21.18% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2019-04-22
Last modified2026-06-17

Affected (40)

VendorProduct
zyxelatp200
zyxelatp200 firmware
zyxelatp500
zyxelatp500 firmware
zyxelatp800
zyxelatp800 firmware
zyxelusg110
zyxelusg110 firmware
zyxelusg1100
zyxelusg1100 firmware
zyxelusg1900
zyxelusg1900 firmware
zyxelusg20-vpn
zyxelusg20-vpn firmware
zyxelusg20w-vpn
zyxelusg20w-vpn firmware
zyxelusg210
zyxelusg210 firmware
zyxelusg2200-vpn
zyxelusg2200-vpn firmware
zyxelusg310
zyxelusg310 firmware
zyxelusg40
zyxelusg40 firmware
zyxelusg40w
zyxelusg40w firmware
zyxelusg60
zyxelusg60 firmware
zyxelusg60w
zyxelusg60w firmware
zyxelvpn100
zyxelvpn100 firmware
zyxelvpn50
zyxelvpn50 firmware
zyxelzywall 110
zyxelzywall 110 firmware
zyxelzywall 1100
zyxelzywall 1100 firmware
zyxelzywall 310
zyxelzywall 310 firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD