CVE-2017-17550: CSRF
Published Nov 10, 2018
·Updated
ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This account's access could, for example, subsequently be used for stored XSS.
Affected Software
3 affected components
Zyxel Zywall Usg 100 Firmware=2.12\(aqq.2\)
Zyxel Zywall Usg 100
Zyxel Zywall Usg 100 Firmware=3.30\(aqq.7\)
Event History
Nov 10, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-17550?
The severity of CVE-2017-17550 is high, with a severity value of 8.8.
2
How are ZyXEL ZyWALL USG devices affected by CVE-2017-17550?
ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability.
3
What is the impact of CVE-2017-17550?
The vulnerability allows an attacker to perform Cross-Site Request Forgery (CSRF) and potentially execute stored XSS attacks.
4
How can I mitigate CVE-2017-17550?
Apply the latest firmware update provided by ZyXEL to fix the CSRF vulnerability.
5
Where can I find more information about CVE-2017-17550?
You can find more information about CVE-2017-17550 at https://www.shellcode.it/article/cve-2017-17550/