CVE-2019-9955: XSS
On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mpidx' parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-9955?
CVE-2019-9955 is a vulnerability that affects Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices.
What is the impact of CVE-2019-9955?
CVE-2019-9955 allows an attacker to execute arbitrary scripts in the context of a user's browser session, potentially allowing them to steal sensitive information or perform malicious actions.
How can I check if my device is affected by CVE-2019-9955?
Check if your Zyxel device is using firmware version 4.31, and if it belongs to one of the affected models listed in the CVE description.
How can I mitigate CVE-2019-9955?
Update your Zyxel device to the latest firmware version, which resolves the vulnerability.
Where can I find more information about CVE-2019-9955?
You can find more information about CVE-2019-9955 on the provided external references: packetstormsecurity.com, seclists.org, and exploit-db.com.