Medium severity5.5NVD Advisory· Published Nov 7, 2023· Updated Jun 17, 2026
CVE-2023-35140
CVE-2023-35140
Description
The improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could allow an authenticated local user with read-only access to modify system settings on a vulnerable device.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13cpe:2.3:o:zyxel:gs1900-10hp_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:zyxel:gs1900-10hp_firmware:*:*:*:*:*:*:*:*range: <=2.70\(aazi.5\)
- (no CPE)range: V2.70(ABTO.5)
- cpe:2.3:o:zyxel:gs1900-24ep_firmware:*:*:*:*:*:*:*:*Range: <=2.70\(abto.5\)
- cpe:2.3:o:zyxel:gs1900-24hpv2_firmware:*:*:*:*:*:*:*:*Range: <=2.70\(abtp.5\)
- cpe:2.3:o:zyxel:gs1900-48hpv2_firmware:*:*:*:*:*:*:*:*Range: <=2.70\(abtq.5\)
- Range: V2.70(ABTO.5)
- Range: V2.70(ABTO.5)
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.