Medium severity6.8NVD Advisory· Published Nov 12, 2024· Updated Jun 17, 2026
CVE-2024-8881
CVE-2024-8881
Description
A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with administrator privileges to execute some operating system (OS) commands on an affected device by sending a crafted HTTP request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12cpe:2.3:o:zyxel:gs1900-10hp_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:zyxel:gs1900-10hp_firmware:*:*:*:*:*:*:*:*range: <2.90\(aazi.0\)c0
- (no CPE)range: <= V2.80(AAHN.1)C0
- cpe:2.3:o:zyxel:gs1900-24e_firmware:*:*:*:*:*:*:*:*Range: <2.90\(aahk.0\)c0
- cpe:2.3:o:zyxel:gs1900-24ep_firmware:*:*:*:*:*:*:*:*Range: <2.90\(abto.0\)c0
- cpe:2.3:o:zyxel:gs1900-24hpv2_firmware:*:*:*:*:*:*:*:*Range: <2.90\(abtp.0\)c0
- cpe:2.3:o:zyxel:gs1900-48hpv2_firmware:*:*:*:*:*:*:*:*Range: <2.90\(abtq.0\)c0
- cpe:2.3:o:zyxel:gs1900-8hp_firmware:*:*:*:*:*:*:*:*Range: <2.90\(aahi.0\)c0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.