Vulnerabilities > Zyxel > Gs1900 24Hpv2 Firmware > 2.70.aatp.0.20211208

DATE CVE VULNERABILITY TITLE RISK
2024-11-12 CVE-2024-8881 OS Command Injection vulnerability in Zyxel products
A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with administrator privileges to execute some operating system (OS) commands on an affected device by sending a crafted HTTP request.
low complexity
zyxel CWE-78
6.8
2024-11-12 CVE-2024-8882 Classic Buffer Overflow vulnerability in Zyxel products
A buffer overflow vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with administrator privileges to cause denial of service (DoS) conditions via a crafted URL.
low complexity
zyxel CWE-120
4.5
2024-09-10 CVE-2024-38270 Insufficient Entropy vulnerability in Zyxel products
An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2.80(AAZI.0)C0.
low complexity
zyxel CWE-331
6.5
2022-09-20 CVE-2022-34746 Insufficient Entropy vulnerability in Zyxel products
An insufficient entropy vulnerability caused by the improper use of randomness sources with low entropy for RSA key pair generation was found in Zyxel GS1900 series firmware versions prior to V2.70.
network
high complexity
zyxel CWE-331
5.9