VYPR

GS1900 series

by Zyxel

CVEs (4)

  • CVE-2021-35032MedDec 28, 2021
    risk 0.42cvss 6.4epss 0.00

    A vulnerability in the 'libsal.so' of the Zyxel GS1900 series firmware version 2.60 could allow an authenticated local user to execute arbitrary OS commands via a crafted function call.

  • CVE-2023-35140MedNov 7, 2023
    risk 0.36cvss 5.5epss 0.00

    The improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could allow an authenticated local user with read-only access to modify system settings on a vulnerable device.

  • CVE-2024-38270MedSep 10, 2024
    risk 0.34cvss 5.3epss 0.00

    An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2.80(AAZI.0)C0. This vulnerability could allow a LAN-based attacker a slight…

  • CVE-2021-35030LowJul 26, 2021
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in the CGI program in Zyxel GS1900-8 firmware version V2.60, that did not properly sterilize packet contents and could allow an authenticated, local user to perform a cross-site scripting (XSS) attack via a crafted LLDP packet.