Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This account's access could, for example, subsequently be used for stored XSS.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ZyXEL ZyWALL USG 跨站请求伪造漏洞
Vulnerability Description
ZyXEL ZyWALL USG是合勤(ZyXEL)科技公司的一款网络安全防火墙设备。 ZyXEL ZyWALL USG 2.12 AQQ.2版本和3.30 AQQ.7版本中存在跨站请求伪造漏洞。远程攻击者可借助‘cmd’参数利用该漏洞添加用户账户,实施跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A