CVE-2021-46387
Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting (XSS)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads to bypass security restriction to achieve Cross Site Scripting, which allows an attacker able to execute arbitrary JavaScript codes to perform multiple attacks such as clipboard hijacking and session hijacking.
ZyXEL ZyWALL 2 Plus Internet Security Appliance está afectado por una vulnerabilidad de tipo Cross Site Scripting (XSS). Un manejo no seguro de URI conlleva a omitir la restricción de seguridad para lograr una vulnerabilidad de tipo Cross Site Scripting, lo que permite a un atacante capaz de ejecutar códigos JavaScript arbitrarios para llevar a cabo múltiples ataques como el secuestro del portapapeles y el secuestro de la sesión.
Zyxel ZyWALL 2 Plus suffers from a cross site scripting vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-01-18 CVE Reserved
- 2022-03-01 CVE Published
- 2022-03-02 First Exploit
- 2024-08-04 CVE Updated
- 2024-10-05 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (5)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.zyxel.com/uk/en/products_services/zywall_2_plus.shtml | 2022-03-09 | |
https://www.zyxel.com/us/en/support/security_advisories.shtml | 2022-03-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zyxel Search vendor "Zyxel" | Zywall 2 Plus Internet Security Appliance Firmware Search vendor "Zyxel" for product "Zywall 2 Plus Internet Security Appliance Firmware" | - | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Zywall 2 Plus Internet Security Appliance Search vendor "Zyxel" for product "Zywall 2 Plus Internet Security Appliance" | - | - |
Safe
|