8.8
CVSSv3

CVE-2017-17550

Published: 10/11/2018 Updated: 13/12/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This account's access could, for example, subsequently be used for stored XSS.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zyxel zywall usg 100 firmware 2.12(aqq.2)

zyxel zywall usg 100 firmware 3.30(aqq.7)