PT-2019-4088 · Zyxel · Zyxel Gs1900
Jasper Lievisse Adriaanse
·
Published
2019-11-14
·
Updated
2020-08-24
·
CVE-2019-15804
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Zyxel GS1900 devices with firmware prior to 2.50(AAHH.0)C0
Description
An issue exists due to insufficient input validation in the Password Recovery component of Zyxel GS1900 series routers. This issue can be triggered by sending a specific signal to the CLI process, such as the SIGQUIT signal, which can be sent through CTRL+ via SSH, allowing access to an undocumented menu. The menu contains "Password recovery for specific user" options, although access control checks are in place to prohibit accessing this menu. The issue may also be accessible using a serial console. Exploitation of this issue could allow a remote attacker to impact the integrity of protected information.
Recommendations
For Zyxel GS1900 devices with firmware prior to 2.50(AAHH.0)C0, update the firmware to version 2.50(AAHH.0)C0 or later to resolve the issue. As a temporary workaround, consider restricting access to the CLI application and the Password Recovery menu to minimize the risk of exploitation. Avoid using the SIGQUIT signal to the CLI application until the issue is resolved.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zyxel Gs1900