CVE-2019-9955 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Zyxel firmware affects v. 4.31.


CVE-2019-9955 Scanner Detail

Zyxel firmware is a security firewall that is used to protect digital assets against cyberattacks. This firmware is used in a wide range of devices such as ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, and ZyWALL 1100. Zyxel firmware is designed to provide multi-layer protection against various types of cyber threats.

CVE-2019-9955 is a vulnerability that has been detected in the security firewall login page of Zyxel firmware. This vulnerability occurs due to the unsanitized 'mp_idx' parameter. Hackers can take advantage of this vulnerability and execute a Reflected XSS attack. This attack can be executed by sending a visitor a malicious link that contains the payload. The attacker can then steal the victim's sensitive information such as login credentials and personal details.

This vulnerability can lead to severe damage to a digital asset. Hackers can use the stolen information for various malicious purposes such as identity theft, financial fraud, and data breaches. Furthermore, they can also use the stolen information to launch more sophisticated cyber-attacks that could potentially shut down entire systems or networks.



