VYPR
Unrated severityNVD Advisory· Published Nov 12, 2024· Updated Nov 12, 2024

CVE-2024-8881

CVE-2024-8881

Description

A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with administrator privileges to execute some operating system (OS) commands on an affected device by sending a crafted HTTP request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Post-authentication command injection in Zyxel GS1900-48 switch CGI allows authenticated admin to execute OS commands via crafted HTTP request.

Vulnerability

A post-authentication command injection vulnerability exists in the CGI program of Zyxel GS1900-48 switches running firmware version V2.80(AAHN.1)C0 and earlier. An authenticated attacker with administrator privileges can exploit this by sending a crafted HTTP request to the affected device's CGI interface. The vulnerability is present because user-supplied input is not properly sanitized before being used in OS command execution [1].

Exploitation

To exploit this vulnerability, an attacker must have LAN access and be authenticated as an administrator on the target switch. The attacker then sends a specially crafted HTTP request to the CGI program, which results in the injection of arbitrary OS commands. No user interaction beyond the initial authentication is required; the attack can be carried out programmatically [1].

Impact

Successful exploitation allows an authenticated administrator to execute arbitrary OS commands on the affected device. This could lead to full compromise of the switch, including the ability to modify configuration, exfiltrate network data, or use the device as a pivot point for further attacks within the network. The impact is limited by the requirement for prior administrative authentication [1].

Mitigation

Zyxel has released firmware patches for affected GS1900 series switches. Users should upgrade to the fixed firmware version as indicated in the vendor's security advisory. For the GS1900-48, the fixed version is V2.80(AAHN.2)C0 or later. No effective workaround is available; the only mitigation is installing the patch. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.