CVE-2022-45441: XSS
A cross-site scripting (XSS) vulnerability in Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.13)C0, which could allow an attacker to store malicious scripts in the Logs page of the GUI on a vulnerable device. A successful XSS attack could force an authenticated user to execute the stored malicious scripts and then result in a denial-of-service (DoS) condition when the user visits the Logs page of the GUI on the device.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-45441?
CVE-2022-45441 is a cross-site scripting (XSS) vulnerability in Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.13)C0.
How does CVE-2022-45441 work?
CVE-2022-45441 allows an attacker to store malicious scripts in the Logs page of the GUI on a vulnerable Zyxel NBG-418N v2 device.
What is the severity of CVE-2022-45441?
The severity of CVE-2022-45441 is high with a CVSS score of 6.1.
How can I fix CVE-2022-45441?
To fix CVE-2022-45441, update the Zyxel NBG-418N v2 firmware to V1.00(AARP.13)C0 or later.
Where can I find more information about CVE-2022-45441?
More information about CVE-2022-45441 can be found in the Zyxel security advisory at https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-xss-vulnerability-in-nbg-418n-v2-home-router.