CVE-2019-13495: Zyxel XGS2210-52hp Firmware

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

In firmware version 4.50 of Zyxel XGS2210-52HP, multiple stored cross-site scripting (XSS) issues allows remote authenticated users to inject arbitrary web script via an rpSys.html Name or Location field.

Affected products

  • Zyxel XGS2210-52hp Firmware: version 4.50 only

Published 2020-03-31. Last modified 2026-06-17.