PT-2019-4088 · Zyxel · Zyxel Gs1900

Jasper Lievisse Adriaanse

·

Published

2019-11-14

·

Updated

2020-08-24

·

CVE-2019-15804

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Zyxel GS1900 devices with firmware prior to 2.50(AAHH.0)C0
Description An issue exists due to insufficient input validation in the Password Recovery component of Zyxel GS1900 series routers. This issue can be triggered by sending a specific signal to the CLI process, such as the SIGQUIT signal, which can be sent through CTRL+ via SSH, allowing access to an undocumented menu. The menu contains "Password recovery for specific user" options, although access control checks are in place to prohibit accessing this menu. The issue may also be accessible using a serial console. Exploitation of this issue could allow a remote attacker to impact the integrity of protected information.
Recommendations For Zyxel GS1900 devices with firmware prior to 2.50(AAHH.0)C0, update the firmware to version 2.50(AAHH.0)C0 or later to resolve the issue. As a temporary workaround, consider restricting access to the CLI application and the Password Recovery menu to minimize the risk of exploitation. Avoid using the SIGQUIT signal to the CLI application until the issue is resolved.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04656
CVE-2019-15804

Affected Products

Zyxel Gs1900