Home/Product/zyxel gs1900 10hp firmware
Product

zyxel gs1900 10hp firmware

30 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-8882
< 2.90\(aazi.0\)c0
A buffer overflow vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier cou
4.5MEDIUM
CVE-2024-8881
< 2.90\(aazi.0\)c0
A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN
6.8MEDIUM
CVE-2024-38270
< 2.80\(aazi.1\)c0
An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication
5.3MEDIUM
CVE-2023-35140
<= 2.70\(aazi.5\)
The improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could allow an aut
5.5MEDIUM
CVE-2022-45853
all versions
The privilege escalation vulnerability in the Zyxel GS1900-8 firmware version V2.70(AAHH.3) and the GS1900-8HP firmware version
6.7MEDIUM
CVE-2022-34746
< 2.70\(aazi.3\)c0
An insufficient entropy vulnerability caused by the improper use of randomness sources with low entropy for RSA key pair generatio
5.9MEDIUM
CVE-2021-35032
< 2.70\(aazi.0\)-20211208
A vulnerability in the 'libsal.so' of the Zyxel GS1900 series firmware version 2.60 could allow an authenticated local user to exe
6.4MEDIUM
CVE-2021-35031
< 2.70\(aazi.0\)-20211208
A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which co
6.8MEDIUM
CVE-2021-35030
< 2.70
A vulnerability was found in the CGI program in Zyxel GS1900-8 firmware version V2.60, that did not properly sterilize packet cont
3.5LOW
CVE-2019-15804
< 2.50\(aazi.0\)c0
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. By sending a signal to the CLI process, undoc
7.5HIGH
CVE-2019-15803
< 2.50\(aazi.0\)c0
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Through an undocumented sequence of keypresse
9.1CRITICAL
CVE-2019-15802
< 2.50\(aazi.0\)c0
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware hashes and encrypts passwords us
5.9MEDIUM
CVE-2019-15801
< 2.50\(aazi.0\)c0
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware image contains encrypted passwor
7.5HIGH
CVE-2019-15800
< 2.50\(aazi.0\)c0
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in the cmd_sy
9.8CRITICAL
CVE-2019-15799
< 2.50\(aazi.0\)c0
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. User accounts created through the web interfa
8.8HIGH
CVE-2016-1346
< 2.50\(aazi.0\)c0
The kernel in Cisco TelePresence Server 3.0 through 4.2(4.18) on Mobility Services Engine (MSE) 8710 devices allows remote attacke
5.9MEDIUM
CVE-2015-6313
< 2.50\(aazi.0\)c0
Cisco TelePresence Server 4.1(2.29) through 4.2(4.17) on 7010; Mobility Services Engine (MSE) 8710; Multiparty Media 310, 320, and
7.5HIGH
CVE-2015-6312
< 2.50\(aazi.0\)c0
Cisco TelePresence Server 3.1 on 7010, Mobility Services Engine (MSE) 8710, Multiparty Media 310 and 320, and Virtual Machine (VM)
7.5HIGH
CVE-2016-1350
< 2.50\(aazi.0\)c0
Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager allow remote attackers to cause a
7.5HIGH
CVE-2016-1349
< 2.50\(aazi.0\)c0
The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to ca
7.5HIGH
CVE-2016-1348
< 2.50\(aazi.0\)c0
Cisco IOS 15.0 through 15.5 and IOS XE 3.3 through 3.16 allow remote attackers to cause a denial of service (device reload) via a
7.5HIGH
CVE-2016-1344
< 2.50\(aazi.0\)c0
The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote attackers to cause a denial of s
5.9MEDIUM
CVE-2015-6260
< 2.50\(aazi.0\)c0
Cisco NX-OS 7.1(1)N1(1) on Nexus 5500, 5600, and 6000 devices does not properly validate PDUs in SNMP packets, which allows remote
7.5HIGH
CVE-2015-0718
< 2.50\(aazi.0\)c0
Cisco NX-OS 4.0 through 6.1 on Nexus 1000V 3000, 4000, 5000, 6000, and 7000 devices and Unified Computing System (UCS) platforms a
7.5HIGH
CVE-2016-1329
< 2.50\(aazi.0\)c0
Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 350
9.8CRITICAL
CVE-2016-1319
< 2.50\(aazi.0\)c0
Cisco Unified Communications Manager (aka CallManager) 9.1(2.10000.28), 10.5(2.10000.5), 10.5(2.12901.1), and 11.0(1.10000.10); Un
5.3MEDIUM
CVE-2016-1317
< 2.50\(aazi.0\)c0
Cisco Unified Communications Manager 11.5(0.98000.480) allows remote authenticated users to obtain sensitive database table-name a
4.3MEDIUM
CVE-2016-1307
< 2.50\(aazi.0\)c0
The Openfire server in Cisco Finesse Desktop 10.5(1) and 11.0(1) and Unified Contact Center Express 10.6(1) has a hardcoded accoun
5.4MEDIUM
CVE-2016-1302
< 2.50\(aazi.0\)c0
Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 90
8.8HIGH
CVE-2015-6398
< 2.50\(aazi.0\)c0
Cisco Nexus 9000 Application Centric Infrastructure (ACI) Mode switches with software before 11.0(1c) allow remote attackers to ca
7.5HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin