Overview
- Description
- A cross-site scripting (XSS) vulnerability in Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.13)C0, which could allow an attacker to store malicious scripts in the Logs page of the GUI on a vulnerable device. A successful XSS attack could force an authenticated user to execute the stored malicious scripts and then result in a denial-of-service (DoS) condition when the user visits the Logs page of the GUI on the device.
- Source
- security@zyxel.com.tw
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 6.1
- Impact score
- 2.7
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:zyxel:nbg-418n:v2:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B864E108-4477-4D56-B635-95A4B5F86AE1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:zyxel:nbg-418n_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4C634CD0-9066-41F5-83F5-AE3AB68A85F4", "versionEndIncluding": "1.00\\(aarp.10\\)c0" } ], "operator": "OR" } ], "operator": "AND" } ]