S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2019-12581 Scanner

CVE-2019-12581 scanner - Cross-Site Scripting (XSS) vulnerability in Zyxel ZyWall, USG, and UAG devices

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-12581
6.1
CVSS

A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows remote attackers to inject arbitrary web script or HTML via the err_msg parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Zyxel ZyWall, USG, and UAG devices are commonly used for secure network connectivity for small to medium-sized businesses and enterprises. They provide firewall, VPN, and content filtering capabilities to ensure secure connectivity through various types of networks. These devices function as a gateway between the internal and external network, thus ensuring the security of sensitive data and preventing unauthorized access.

However, a critical vulnerability, CVE-2019-12581, has been identified that affects these devices. This vulnerability allows remote attackers to inject arbitrary web scripts or HTML through the "err_msg" parameter in the free_time_failed.cgi program. This injection allows hackers to execute potentially malicious code on the targeted devices and gain unauthorized access to the network and its sensitive data.

Vulnerable Devices and Versions

Device Vulnerability Firmware Version
UAG2100 XSS (CVE-2019-12581) 4.18(AAIZ.1)C0 and earlier
UAG4100 XSS (CVE-2019-12581) 4.18(AATD.1)C0 and earlier
UAG5100 XSS (CVE-2019-12581) 4.18(AAPN.1)C0 and earlier

When exploited, this vulnerability can lead to the loss of confidential business information, financial loss, and severe damage to the business's reputation. Moreover, there is a risk of legal action taken against the organization that fails to protect its data and clients.

s4e.io offers pro features that enable businesses to easily and quickly learn about vulnerabilities in their digital assets. With the platform's comprehensive vulnerability assessment tools, organizations can identify, prioritize, and mitigate threats to their networks and devices. By utilizing the various security features offered by s4e.io, businesses can ensure that they have taken the necessary steps to protect their sensitive data and maintain their reputation.

 

REFERENCES

Solution Advice

To protect against this vulnerability, organizations should take the following precautions:

  • Ensure that the device is running the latest firmware version.
  • Disable external access to the device's web interface.
  • Use a strong and unique password for the device's admin account.
  • Regularly monitor network traffic to detect and block any malicious code being executed on the device.
  • Implement a "deny-by-default" policy that restricts all external inbound traffic by default.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-12581 scanner - Cross-Site Scripting (XSS) vulnerability in Zyxel ZyWall, USG, and UAG devices S4E