CVE-2017-17550
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This account's access could, for example, subsequently be used for stored XSS.
Affected (2)
Products: Zyxel: Zywall Usg 100 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.12(aqq.2) |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.30(aqq.7) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Zywall Usg 100 | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.