Fiche vulnérabilité
CVE-2021-35031 : faille élevée zyxel gs1900-8 firmware (CVSS 8.0)
Description
A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authenticated LAN user to execute arbitrary OS commands via the GUI of the vulnerable device.
En bref
- Sévérité
- Élevée (CVSS 8.0)
- Vecteur CVSS
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 28 déc. 2021
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- zyxel gs1900-8 firmware
- zyxel gs1900-8hp firmware
- zyxel gs1900-10hp firmware
- zyxel gs1900-16 firmware
- zyxel gs1900-24e firmware
- zyxel gs1900-24ep firmware
- zyxel gs1900-24 firmware
- zyxel gs1900-24hp firmware
- zyxel gs1900-24hpv2 firmware
- zyxel gs1900-48 firmware
- zyxel gs1900-48hp firmware
- zyxel gs1900-48hpv2 firmware
- zyxel xgs1210-12 firmware
- zyxel xgs1250-12 firmware