Detects 'Cross-Site Scripting (XSS)' vulnerability in ZyXEL ZyWALL 2 Plus Internet Security Appliance affects v. Unknown.


The ZyXEL ZyWALL 2 Plus Internet Security Appliance is a security device designed to protect networks and devices from online threats. It works by blocking malicious traffic and enabling secure connections between devices, servers, and the internet. This device is commonly used in small and medium-sized businesses to secure their networks and data.

One major vulnerability detected in this product is identified as CVE-2021-46387. This vulnerability arises from an insecure URI handling that can bypass security restrictions, ultimately leading to cross-site scripting (XSS) attacks. When exploited, an attacker can execute arbitrary JavaScript code on the victim's device, potentially gaining access to sensitive data such as user credentials, personal information, and financial details.

If this vulnerability is exploited, attackers can perform multiple attacks like clipboard hijacking and session hijacking. This can lead to identity theft, data breaches and loss of sensitive information. The attacker can also use this vulnerability to spread malware and ransomware, which could cripple the victim's network and lead to financial losses.

