XSS Vulnerability in Zyxel NBG-418N v2 Router Firmware
CVE-2023-22921
7.5HIGH
Summary
A cross-site scripting (XSS) vulnerability exists in the Zyxel NBG-418N v2 router, particularly in firmware versions prior to V1.00(AARP.14)C0. This flaw enables a remote authenticated attacker with administrator privileges to inject malicious scripts through the web management interface. If exploited, it can lead to denial-of-service (DoS) conditions, compromising the device's availability and security. It is crucial for users to update to the latest firmware to mitigate risks associated with this vulnerability.
Affected Version(s)
NBG-418N v2 firmware < V1.00(AARP.14)C0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved