Vulnerabilities > Zyxel > Gs1900 24Hpv2 Firmware

DATE CVE VULNERABILITY TITLE RISK
2023-11-07 CVE-2023-35140 Improper Privilege Management vulnerability in Zyxel products
The improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could allow an authenticated local user with read-only access to modify system settings on a vulnerable device.
local
low complexity
zyxel CWE-269
5.5
2023-05-30 CVE-2022-45853 Unspecified vulnerability in Zyxel products
The privilege escalation vulnerability in the Zyxel GS1900-8 firmware version V2.70(AAHH.3) and the GS1900-8HP firmware version V2.70(AAHI.3) could allow an authenticated, local attacker with administrator privileges to execute some system commands as 'root' on a vulnerable device via SSH.
local
low complexity
zyxel
6.7
2021-12-28 CVE-2021-35031 OS Command Injection vulnerability in Zyxel products
A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authenticated LAN user to execute arbitrary OS commands via the GUI of the vulnerable device.
low complexity
zyxel CWE-78
7.7
2021-12-28 CVE-2021-35032 OS Command Injection vulnerability in Zyxel products
A vulnerability in the 'libsal.so' of the Zyxel GS1900 series firmware version 2.60 could allow an authenticated local user to execute arbitrary OS commands via a crafted function call.
local
low complexity
zyxel CWE-78
7.2
2021-07-26 CVE-2021-35030 Cross-site Scripting vulnerability in Zyxel products
A vulnerability was found in the CGI program in Zyxel GS1900-8 firmware version V2.60, that did not properly sterilize packet contents and could allow an authenticated, local user to perform a cross-site scripting (XSS) attack via a crafted LLDP packet.
2.3