漏洞描述
Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, and ZyWALL 1100 devices contain a reflected cross-site scripting vulnerability on the security firewall login page via the mp_idx parameter.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
packetstormsecurity.comhttp://packetstormsecurity.com/files/152525/Zyxel-ZyWall-Cross-Site-Scripting.html↗www.securitymetrics.comhttps://www.securitymetrics.com/blog/Zyxel-Devices-Vulnerable-Cross-Site-Scripting-Login-page↗www.zyxel.comhttps://www.zyxel.com/support/reflected-cross-site-scripting-vulnerability-of-firewalls.shtml↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2019-9955↗