Cross-Site Scripting Vulnerability in Zyxel ATP and USG FLEX Firmware
CVE-2023-35139
Key Information:
- Vendor
Zyxel
- Status
- Vendor
- CVE Published:
- 28 November 2023
What is CVE-2023-35139?
A cross-site scripting vulnerability exists in the CGI program of Zyxel's ATP series and USG FLEX series firmware. This flaw affects multiple firmware versions, allowing unauthenticated LAN-based attackers to store malicious scripts on vulnerable devices. If exploited, these scripts may execute and lead to the theft of cookies when users access specific CGIs used for ZTP log dumping. This vulnerability poses a significant risk to affected products by enabling attackers to manipulate sessions and extract sensitive information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
USG FLEX 50(W) series firmware versions 5.10 through 5.37
ATP series firmware versions 5.10 through 5.37
USG FLEX series firmware versions 5.00 through 5.37
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved