CVE-2019-9955: Zyxel ATP200 Firmware
Medium severity, CVSS 6.1. EPSS: 21.2% chance of exploitation in the next 30 days.
On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter.
Affected products
- Zyxel ATP200 Firmware: version 4.31 only
- Zyxel ATP500 Firmware: version 4.31 only
- Zyxel ATP800 Firmware: version 4.31 only
- Zyxel USG1100 Firmware: version 4.31 only
- Zyxel USG110 Firmware: version 4.31 only
- Zyxel USG1900 Firmware: version 4.31 only
- Zyxel USG20-VPN Firmware: version 4.31 only
- Zyxel USG20W-VPN Firmware: version 4.31 only
- Zyxel USG210 Firmware: version 4.31 only
- Zyxel USG2200-VPN Firmware: version 4.31 only
- Zyxel USG310 Firmware: version 4.31 only
- Zyxel USG40 Firmware: version 4.31 only
- Zyxel USG40W Firmware: version 4.31 only
- Zyxel USG60 Firmware: version 4.31 only
- Zyxel USG60W Firmware: version 4.31 only
- Zyxel VPN100 Firmware: affected versions not specified
- Zyxel VPN300 Firmware: affected versions not specified
- Zyxel VPN50 Firmware: affected versions not specified
- Zyxel Zywall 1100 Firmware: version 4.31 only
- Zyxel Zywall 110 Firmware: version 4.31 only
- Zyxel Zywall 310 Firmware: version 4.31 only
Published 2019-04-22. Last modified 2026-06-17.