Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Simone Cardona

#30920de 56,333
8.8CVSS total
Vulnerabilidades · 1
PT-2018-6532
8.8
2018-11-10
Zyxel · Zywall/Usg · CVE-2017-17550
Name of the Vulnerable Software and Affected Versions: ZyXEL ZyWALL USG versions 2.12 AQQ.2 through 3.30 AQQ.7 Description: The issue allows for a CSRF attack via the "cgi-bin/zysh-cgi" endpoint with a `cmd` action to add a user account. This added account could then be used for stored XSS attacks. Recommendations: For versions 2.12 AQQ.2 through 3.30 AQQ.7, as a temporary workaround, consider restricting access to the "cgi-bin/zysh-cgi" endpoint to minimize the risk of exploitation. Avoid using the `cmd` action in this endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.