Medium severity5.3NVD Advisory· Published Sep 10, 2024· Updated Jun 17, 2026
CVE-2024-38270
CVE-2024-38270
Description
An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2.80(AAZI.0)C0. This vulnerability could allow a LAN-based attacker a slight chance to gain a valid session token if multiple authenticated sessions are alive.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13cpe:2.3:o:zyxel:gs1900-10hp_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:zyxel:gs1900-10hp_firmware:*:*:*:*:*:*:*:*range: <2.80\(aazi.1\)c0
- (no CPE)range: V2.80(AAZI.0)C0
- cpe:2.3:o:zyxel:gs1900-24e_firmware:*:*:*:*:*:*:*:*Range: <=2.80\(aahk.1\)c0
- cpe:2.3:o:zyxel:gs1900-24ep_firmware:*:*:*:*:*:*:*:*Range: <2.80\(abto.1\)c0
- cpe:2.3:o:zyxel:gs1900-24hpv2_firmware:*:*:*:*:*:*:*:*Range: <2.80\(abtp.1\)c0
- cpe:2.3:o:zyxel:gs1900-48hpv2_firmware:*:*:*:*:*:*:*:*Range: <2.80\(abtq.1\)c0
- cpe:2.3:o:zyxel:gs1900-8hp_firmware:*:*:*:*:*:*:*:*Range: <2.80\(aahi.1\)c0
- Range: V2.80(AAZI.0)C0
- Range: V2.80(AAZI.0)C0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.