PT-2021-6107 · Zyxel · Zyxel Gs1900 Series+2
Published
2021-12-28
·
Updated
2022-01-07
·
CVE-2021-35031
CVSS v3.1
8.0
High
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zyxel GS1900 series firmware (affected versions not specified)
Zyxel XGS1210 series firmware (affected versions not specified)
Zyxel XGS1250 series firmware (affected versions not specified)
Description
A vulnerability in the TFTP client of the affected Zyxel firmware could allow an authenticated LAN user to execute arbitrary OS commands via the GUI of the vulnerable device. The issue is related to the failure to neutralize special elements, which could enable a remote attacker to perform arbitrary commands through the graphical interface.
Recommendations
For Zyxel GS1900 series firmware, update to a version that addresses the TFTP client vulnerability.
For Zyxel XGS1210 series firmware, update to a version that addresses the TFTP client vulnerability.
For Zyxel XGS1250 series firmware, update to a version that addresses the TFTP client vulnerability.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zyxel Gs1900 Series
Zyxel Xgs1210 Series
Zyxel Xgs1250 Series