CVE-2022-40603
—CVSS 3.1
6.1 medium
EPSS
<1%p29
Published
()
Modified
Description
A cross-site scripting (XSS) vulnerability in the CGI program of Zyxel ZyWALL/USG series firmware versions 4.30 through 4.72, VPN series firmware versions 4.30 through 5.31, USG FLEX series firmware versions 4.50 through 5.31, and ATP series firmware versions 4.32 through 5.31, which could allow an attacker to trick a user into visiting a crafted URL with the XSS payload. Then, the attacker could gain access to some browser-based information if the malicious script is executed on the victim’s browser.
- Vendors
- zyxel
- Products
- atp800 firmware, atp700 firmware, atp500 firmware, atp200 firmware, atp100 firmware, atp100w firmware, usg flex 100w firmware, usg flex 200 firmware, usg flex 500 firmware, usg flex 700 firmware, usg flex 50w firmware, vpn1000 firmware
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.