PT-2021-6107 · Zyxel · Zyxel Gs1900 Series+2

Published

2021-12-28

·

Updated

2022-01-07

·

CVE-2021-35031

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zyxel GS1900 series firmware (affected versions not specified) Zyxel XGS1210 series firmware (affected versions not specified) Zyxel XGS1250 series firmware (affected versions not specified)
Description A vulnerability in the TFTP client of the affected Zyxel firmware could allow an authenticated LAN user to execute arbitrary OS commands via the GUI of the vulnerable device. The issue is related to the failure to neutralize special elements, which could enable a remote attacker to perform arbitrary commands through the graphical interface.
Recommendations For Zyxel GS1900 series firmware, update to a version that addresses the TFTP client vulnerability. For Zyxel XGS1210 series firmware, update to a version that addresses the TFTP client vulnerability. For Zyxel XGS1250 series firmware, update to a version that addresses the TFTP client vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00845
CVE-2021-35031

Affected Products

Zyxel Gs1900 Series
Zyxel Xgs1210 Series
Zyxel Xgs1250 Series