← Volver a CVEs
CVE-2021-35031
MEDIUM6.8
Descripcion
A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authenticated LAN user to execute arbitrary OS commands via the GUI of the vulnerable device.
Detalles CVE
Puntuacion CVSS v3.16.8
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueADJACENT_NETWORK
ComplejidadLOW
Privilegios requeridosHIGH
Interaccion usuarioNONE
Publicado12/28/2021
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
zyxel:gs1900-10hpzyxel:gs1900-10hp_firmwarezyxel:gs1900-16zyxel:gs1900-16_firmwarezyxel:gs1900-24zyxel:gs1900-24_firmwarezyxel:gs1900-24ezyxel:gs1900-24e_firmwarezyxel:gs1900-24epzyxel:gs1900-24ep_firmwarezyxel:gs1900-24hpzyxel:gs1900-24hp_firmwarezyxel:gs1900-24hpv2zyxel:gs1900-24hpv2_firmwarezyxel:gs1900-48zyxel:gs1900-48_firmwarezyxel:gs1900-48hpzyxel:gs1900-48hp_firmwarezyxel:gs1900-48hpv2zyxel:gs1900-48hpv2_firmwarezyxel:gs1900-8zyxel:gs1900-8_firmwarezyxel:gs1900-8hpzyxel:gs1900-8hp_firmwarezyxel:xgs1210-12zyxel:xgs1210-12_firmwarezyxel:xgs1250-12zyxel:xgs1250-12_firmware
Debilidades (CWE)
CWE-78CWE-78
Referencias
https://www.zyxel.com/support/Zyxel_security_advisory_for_OS_command_injection_vulnerabilities_of_switches.shtml(security@zyxel.com.tw)
https://www.zyxel.com/support/Zyxel_security_advisory_for_OS_command_injection_vulnerabilities_of_switches.shtml(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.