Medium severity6.8NVD Advisory· Published Dec 28, 2021· Updated Jun 17, 2026
CVE-2021-35031
CVE-2021-35031
Description
A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authenticated LAN user to execute arbitrary OS commands via the GUI of the vulnerable device.
Affected products
19cpe:2.3:o:zyxel:gs1900-10hp_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:zyxel:gs1900-10hp_firmware:*:*:*:*:*:*:*:*range: <2.70\(aazi.0\)-20211208
- (no CPE)range: 2.60
- cpe:2.3:o:zyxel:gs1900-16_firmware:*:*:*:*:*:*:*:*Range: <2.70\(aahj.0\)-20211208
- cpe:2.3:o:zyxel:gs1900-24_firmware:*:*:*:*:*:*:*:*Range: <2.70\(aahl.0\)-20211208
- cpe:2.3:o:zyxel:gs1900-24e_firmware:*:*:*:*:*:*:*:*Range: <2.70\(aahk.0\)-20211208
- cpe:2.3:o:zyxel:gs1900-24ep_firmware:*:*:*:*:*:*:*:*Range: <2.70\(abto.0\)-20211208
- cpe:2.3:o:zyxel:gs1900-24hp_firmware:*:*:*:*:*:*:*:*Range: <2.70\(aahm.0\)-20211208
- cpe:2.3:o:zyxel:gs1900-24hpv2_firmware:*:*:*:*:*:*:*:*Range: <2.70\(aatp.0\)-20211208
- cpe:2.3:o:zyxel:gs1900-48_firmware:*:*:*:*:*:*:*:*Range: <2.70\(aahn.0\)-20211208
- cpe:2.3:o:zyxel:gs1900-48hp_firmware:*:*:*:*:*:*:*:*Range: <2.70\(aaho.0\)-20211208
- cpe:2.3:o:zyxel:gs1900-48hpv2_firmware:*:*:*:*:*:*:*:*Range: <2.70\(abtq.0\)-20211208
- cpe:2.3:o:zyxel:gs1900-8_firmware:*:*:*:*:*:*:*:*Range: <2.70\(aahh.0\)-20211208
- cpe:2.3:o:zyxel:gs1900-8hp_firmware:*:*:*:*:*:*:*:*Range: <2.70\(aahi.0\)-20211208
- cpe:2.3:o:zyxel:xgs1210-12_firmware:*:*:*:*:*:*:*:*Range: <1.00\(abty.5\)c0
- cpe:2.3:o:zyxel:xgs1250-12_firmware:*:*:*:*:*:*:*:*Range: <1.00\(abwe.1\)c0
- Range: 1.00(ABTY.4)C0
- Range: 1.00(ABWE.0)C0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.