CVE-2022-43393
Description
An improper check for unusual or exceptional conditions in the HTTP request processing function of Zyxel GS1920-24v2 firmware prior to V4.70(ABMH.8)C0, which could allow an unauthenticated attacker to corrupt the contents of the memory and result in a denial-of-service (DoS) condition on a vulnerable device.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An improper check in Zyxel GS1920-24v2 HTTP request processing allows unauthenticated memory corruption, leading to DoS.
Vulnerability
An improper check for unusual or exceptional conditions exists in the HTTP request processing function of Zyxel GS1920-24v2 firmware prior to V4.70(ABMH.8)C0. This vulnerability, identified as CVE-2022-43393, allows an unauthenticated attacker to corrupt memory contents, leading to a denial-of-service (DoS) condition. The affected model is the GS1920-24v2 running firmware versions before V4.70(ABMH.8)C0 [1].
Exploitation
An attacker does not require authentication and can exploit this vulnerability by sending specially crafted HTTP requests to the device's management interface over the network. The vulnerability resides in the HTTP request processing function, and successful exploitation triggers memory corruption that causes the device to crash or become unresponsive [1].
Impact
Successful exploitation results in a denial-of-service (DoS) condition, rendering the affected switch unavailable for normal network operations. The attack impacts availability, but no information disclosure or remote code execution has been reported [1].
Mitigation
Zyxel has released patched firmware version V4.70(ABMH.8)C0 for the GS1920-24v2 to address this vulnerability. Users are advised to update to this version. As switches are typically deployed in LAN environments, firewall restrictions can reduce exposure. For optimal protection, users should restrict HTTP/HTTPS remote access or limit access to specific IP addresses [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: < V4.70(ABMH.8)C0
- Range: < V4.70(ABMH.8)C0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.