Zyxel ZyWall, USG, and UAG devices allow remote attackers to inject arbitrary web script or HTML via the err_msg parameter free_time_failed.cgi CGI program, aka reflective cross-site scripting.
id: CVE-2019-12581
info:
name: Zyxel ZyWal/USG/UAG Devices - Cross-Site Scripting
author: n-thu
...