← Retour aux CVEs
CVE-2021-35031
MEDIUM6.8
Description
A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authenticated LAN user to execute arbitrary OS commands via the GUI of the vulnerable device.
Details CVE
Score CVSS v3.16.8
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueADJACENT_NETWORK
ComplexiteLOW
Privileges requisHIGH
Interaction utilisateurNONE
Publie12/28/2021
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
zyxel:gs1900-10hpzyxel:gs1900-10hp_firmwarezyxel:gs1900-16zyxel:gs1900-16_firmwarezyxel:gs1900-24zyxel:gs1900-24_firmwarezyxel:gs1900-24ezyxel:gs1900-24e_firmwarezyxel:gs1900-24epzyxel:gs1900-24ep_firmwarezyxel:gs1900-24hpzyxel:gs1900-24hp_firmwarezyxel:gs1900-24hpv2zyxel:gs1900-24hpv2_firmwarezyxel:gs1900-48zyxel:gs1900-48_firmwarezyxel:gs1900-48hpzyxel:gs1900-48hp_firmwarezyxel:gs1900-48hpv2zyxel:gs1900-48hpv2_firmwarezyxel:gs1900-8zyxel:gs1900-8_firmwarezyxel:gs1900-8hpzyxel:gs1900-8hp_firmwarezyxel:xgs1210-12zyxel:xgs1210-12_firmwarezyxel:xgs1250-12zyxel:xgs1250-12_firmware
Faiblesses (CWE)
CWE-78CWE-78
References
https://www.zyxel.com/support/Zyxel_security_advisory_for_OS_command_injection_vulnerabilities_of_switches.shtml(security@zyxel.com.tw)
https://www.zyxel.com/support/Zyxel_security_advisory_for_OS_command_injection_vulnerabilities_of_switches.shtml(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.