S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2019-12583 Scanner

CVE-2019-12583 scanner - Account Creation vulnerability in Zyxel UAG, USG, and ZyWall devices

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-12583
9.1
CVSS

Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access or Denial of Service.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Zyxel UAG, USG, and ZyWall devices are commonly used by businesses and organizations to manage their networks. These devices provide comprehensive security features such as VPN connectivity, firewall protection, and content filtering. The ZyWall series of devices are specifically designed to provide enterprise-grade security services whilst the USG can handle security for branch offices and SMBs. The UAG devices were designed for cloud-managed networks and provide versatile functionality for businesses of all sizes.

The CVE-2019-12583 vulnerability detected in these Zyxel devices involves a missing access control in the "Free Time" component. This loophole allows a remote attacker to access the account generator and create guest accounts without proper authorization. This can lead to unauthorised network access and pose grave security risks. Hackers can use these accounts to gain access to the network silently, steal confidential data, and cause a denial of service.

The exploitation of this vulnerability can pave the way for disastrous consequences. Once hackers have access to the network, they can install malware, carry out DDoS attacks, and cripple the network. The breach of confidential data can lead to devastating reputational damage, lawsuits, and penalties. Moreover, the unauthorized use of network resources can lead to gross financial losses. That's why it's essential to take appropriate precautions against this vulnerability.

At S4E, our platform is equipped with pro features that enable you to quickly learn about vulnerabilities in your digital assets. You can use our vulnerability scanner to identify weaknesses in your network's configuration and remediate them before they are exploited. With advanced reporting and visibility tools, our platform empowers you to secure your network easily and effectively. Protect your digital assets with S4E.

 

REFERENCES

Solution Advice

To protect your network against the CVE-2019-12583 vulnerability, you can:

  • Only grant access to trusted individuals who need access to your network. 
  • Use a strong password for network accounts, and change them regularly.
  • Utilize multi-factor authentication to add an extra layer of security.
  • Conduct regular network scans, implement patches and firmware updates on time.
  • Deploy an intrusion detection system along with a firewall to monitor network traffic.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.