Vendor Description
“Focused on innovation and customer-centricity, Zyxel Communications Corp. has been connecting people to the internet for nearly 30 years. We keep promoting creativity which meets the needs of customers. This spirit has never been changed since we developed the world’s first integrated 3-in-1 data/fax/voice modem in 1992. Our ability to adapt and innovate with networking technology
places us at the forefront of understanding connectivity for telco/service providers, businesses and home users.
We’re building the networks of tomorrow, helping unlock the world’s potential and meeting the needs of the modern workplace; powering people at work, life and play. We stand side-by-side with our customers and partners to share new approaches to networking that will unleash their abilities. Loyal friend, powerful ally, reliable resource — we are Zyxel, Your Networking Ally.”
Source: https://www.zyxel.com/about_zyxel/company_overview.shtml
Business Recommendation
SEC Consult recommends Zyxel customers to upgrade the firmware to the latest version available. A thorough security review should be performed by security professionals to identify further potential security issues.
1. Reflected Cross-Site Scripting (XSS)
A reflected cross-site scripting vulnerability was identified in ‘free_time_failed.cgi’ in the admin interface. The parameter ‘err_msg’ is returned without any sanitization of the input. An attacker, for example, can exploit this vulnerability to steal cookies from the attacked user in order to hijack a session and gain access to the device.
Proof Of Concept
1. Reflected Cross-Site Scripting (XSS)
By opening to the following link, contents of the ‘arip’ and ‘zy_pc_browser’ cookies will be displayed.
<IP-Address>/free_time_failed.cgi; <IP-Address>/free_time_failed.cgi;
Vulnerable / Tested Versions
The following versions are affected:
- Zyxel ZyWall USG 110 ZLD 4.30 and earlier
- Zyxel ZyWall USG 210 ZLD 4.30 and earlier
- Zyxel ZyWall USG 310 ZLD 4.30 and earlier
- Zyxel ZyWall USG 1100 ZLD 4.30 and earlier
- Zyxel ZyWall USG 1900 ZLD 4.30 and earlier
- Zyxel ZyWall USG 2200-VPN ZLD 4.30 and earlier