Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-22921


A cross-site scripting (XSS) vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote authenticated attacker with administrator privileges to store malicious scripts using a web management interface parameter, resulting in denial-of-service (DoS) conditions on an affected device.


Published

2023-05-01T17:15:09.110

Last Modified

2024-11-21T07:45:39.400

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-79
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System zyxel nbg-418n_firmware ≤ 1.00\(aarp.13\)c0 Yes
Hardware zyxel nbg-418n v2 No

References