CVE-2024-42061
MEDIUMDescription
A reflected cross-site scripting (XSS) vulnerability in the CGI program "dynamic_script.cgi" of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and USG20(W)-VPN series firmware versions from V4.16 through V5.38 could allow an attacker to trick a user into visiting a crafted URL with the XSS payload. The attacker could obtain browser-based information if the malicious script is executed on the victim’s browser.
Is your site exposed to CVE-2024-42061?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| zyxel | zld |
| zyxel | atp100 |
| zyxel | atp100w |
| zyxel | atp200 |
| zyxel | atp500 |
| zyxel | atp700 |
| zyxel | atp800 |
| zyxel | zld |
| zyxel | usg_flex_100 |
| zyxel | usg_flex_100ax |
| zyxel | usg_flex_100w |
| zyxel | usg_flex_200 |
| zyxel | usg_flex_50 |
| zyxel | usg_flex_500 |
| zyxel | usg_flex_700 |
| zyxel | zld |
| zyxel | usg_flex_50w |
| zyxel | zld |
| zyxel | usg_20w-vpn |
References
Frequently Asked Questions
What is CVE-2024-42061? +
How severe is CVE-2024-42061? +
What products are affected by CVE-2024-42061? +
How do I check if I'm vulnerable to CVE-2024-42061? +
Related Vulnerabilities
WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows …
Reflected Cross-Site Scripting (XSS) vulnerability in Navigate Content Management System. The vulnerability is present in the '/blog' endpoint because user …
Cross-Site Scripting (XSS) vulnerability reflected in Semantic MediaWiki. This vulnerability allows an attacker to execute JavaScript code in the victim's …
Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that allows unauthenticated attackers …
mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the admin dashboard's Autodiscover …
mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the mailcow web interface …