Critical severity9.1NVD Advisory· Published Jun 27, 2019· Updated Jun 17, 2026
CVE-2019-12583
CVE-2019-12583
Description
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access or Denial of Service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
18- cpe:2.3:o:zyxel:usg2200-vpn_firmware:*:*:*:*:*:*:*:*Range: <=4.33\(abae.0\)c0
- cpe:2.3:o:zyxel:zywall_1100_firmware:*:*:*:*:*:*:*:*Range: <=4.33\(aaac.0\)c0
- cpe:2.3:o:zyxel:zywall_110_firmware:*:*:*:*:*:*:*:*Range: <=4.33\(aaaa.0\)c0
- cpe:2.3:o:zyxel:zywall_310_firmware:*:*:*:*:*:*:*:*Range: <=4.33\(aaab.0\)c0
- cpe:2.3:o:zyxel:zywall_vpn100_firmware:*:*:*:*:*:*:*:*Range: <=10.02\(abfv.0\)c0
- cpe:2.3:o:zyxel:zywall_vpn300_firmware:*:*:*:*:*:*:*:*Range: <=10.02\(abfc.0\)c0
- Zyxel/UAG, USG, and ZyWall devicesdescription
Patches
Vulnerability mechanics
References
2- www.zyxel.com/support/vulnerabilities-related-to-the-Free-Time-feature.shtmlnvdPatchVendor Advisory
- n-thumann.de/blog/zyxel-gateways-missing-access-control-in-account-generator-xss/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.