CVE-2022-0734: XSS
A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.35 through 5.20, and VPN series firmware versions 4.35 through 5.20, that could allow an attacker to obtain some information stored in the user's browser, such as cookies or session tokens, via a malicious script.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-0734?
CVE-2022-0734 has been classified as a high severity cross-site scripting vulnerability.
How do I fix CVE-2022-0734?
To fix CVE-2022-0734, you should update your Zyxel firmware to the latest version that addresses this vulnerability.
What versions of Zyxel firmware are affected by CVE-2022-0734?
CVE-2022-0734 affects Zyxel USG/ZyWALL firmware versions 4.35 to 4.70, USG FLEX versions 4.50 to 5.20, ATP firmware versions 4.35 to 5.20, and VPN firmware versions 4.35 to 5.20.
Is CVE-2022-0734 a remote exploit?
Yes, CVE-2022-0734 can potentially be exploited remotely via malicious web pages.
What devices are impacted by CVE-2022-0734 specifically?
Devices impacted by CVE-2022-0734 include Zyxel VPN, USG, ATP, and ZYWALL series products running the mentioned firmware versions.