S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-46387 Scanner

CVE-2021-46387 scanner - Cross-Site Scripting (XSS) vulnerability in ZyXEL ZyWALL 2 Plus Internet Security Appliance

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-46387
6.1
CVSS

ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads to bypass security restriction to achieve Cross Site Scripting, which allows an attacker able to execute arbitrary JavaScript codes to perform multiple attacks such as clipboard hijacking and session hijacking.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The ZyXEL ZyWALL 2 Plus Internet Security Appliance is a security device designed to protect networks and devices from online threats. It works by blocking malicious traffic and enabling secure connections between devices, servers, and the internet. This device is commonly used in small and medium-sized businesses to secure their networks and data.

One major vulnerability detected in this product is identified as CVE-2021-46387. This vulnerability arises from an insecure URI handling that can bypass security restrictions, ultimately leading to cross-site scripting (XSS) attacks. When exploited, an attacker can execute arbitrary JavaScript code on the victim's device, potentially gaining access to sensitive data such as user credentials, personal information, and financial details.

If this vulnerability is exploited, attackers can perform multiple attacks like clipboard hijacking and session hijacking. This can lead to identity theft, data breaches and loss of sensitive information. The attacker can also use this vulnerability to spread malware and ransomware, which could cripple the victim's network and lead to financial losses.

Thanks to the pro features of the s4e.io platform, readers of this article can easily and quickly learn about vulnerabilities in their digital assets. By signing up for this platform, readers can get access to a range of professional security tools and resources that help protect against online threats. These resources include regular security updates, vulnerability scanners, and expert advice on how to secure networks and devices. With s4e.io, users can ensure the safety and security of their digital assets, keeping them protected from online threats and attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, several precautions can be taken such as:

  • Regularly update and patch the ZyXEL ZyWALL 2 Plus Internet Security Appliance and any other security device in use.
  • Set up strong authentication mechanisms to prevent unauthorized access to the device and network.
  • Conduct regular security audits and penetration tests to identify weaknesses and vulnerabilities.
  • Use security software to detect and block malicious traffic and attacks.
  • Provide regular employee training to educate them on online security threats and how to avoid them.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-46387 scanner - Cross-Site Scripting (XSS) vulnerability in ZyXEL ZyWALL 2 Plus Internet Security Appliance | S4E