4.3
CVSSv2

CVE-2022-0734

Published: 24/05/2022 Updated: 06/06/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35 up to and including 4.70, USG FLEX series firmware versions 4.50 up to and including 5.20, ATP series firmware versions 4.35 up to and including 5.20, and VPN series firmware versions 4.35 up to and including 5.20, that could allow an malicious user to obtain some information stored in the user's browser, such as cookies or session tokens, via a malicious script.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zyxel vpn100_firmware

zyxel vpn1000_firmware

zyxel vpn300_firmware

zyxel vpn50_firmware

zyxel atp100_firmware

zyxel atp100w_firmware

zyxel atp200_firmware

zyxel atp500_firmware

zyxel atp700_firmware

zyxel atp800_firmware

zyxel usg_110_firmware

zyxel usg_1100_firmware

zyxel usg_1900_firmware

zyxel usg_20w_firmware

zyxel usg_20w-vpn_firmware

zyxel usg_2200-vpn_firmware

zyxel usg_310_firmware

zyxel usg_40_firmware

zyxel usg_40w_firmware

zyxel usg_60_firmware

zyxel usg_60w_firmware

zyxel usg_flex_100_firmware

zyxel usg_flex_100w_firmware

zyxel usg_flex_200_firmware

zyxel usg_flex_500_firmware

zyxel usg_flex_700_firmware

zyxel usg200_firmware

zyxel usg20_firmware

zyxel usg210_firmware

zyxel usg2200_firmware

zyxel usg300_firmware

zyxel usg310_firmware