Description
ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This account's access could, for example, subsequently be used for stored XSS.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-8710 | ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This account's access could, for example, subsequently be used for stored XSS. |
References
| Link | Providers |
|---|---|
| https://www.shellcode.it/article/cve-2017-17550/ |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T20:51:32.386Z
Reserved: 2017-12-11T00:00:00.000Z
Link: CVE-2017-17550
No data.
Status : Modified
Published: 2018-11-10T22:29:00.247
Modified: 2024-11-21T03:18:08.590
Link: CVE-2017-17550
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD