CVE-2021-35031

Severity
8.0HIGH
EPSS
0.1%
top 75.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 28
Latest updateDec 29

Description

A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authenticated LAN user to execute arbitrary OS commands via the GUI of the vulnerable device.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.9 | Impact: 5.9

Affected Packages17 packages

CVEListV5zyxel/xgs1210_series_firmware1.00(ABTY.4)C0
CVEListV5zyxel/xgs1250_series_firmware1.00(ABWE.0)C0
NVDzyxel/gs1900-8_firmware< 2.70\(aahh.0\)-20211208
NVDzyxel/gs1900-16_firmware< 2.70\(aahj.0\)-20211208

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xghr-m3mr-m6m9: A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authent2021-12-29
CVEList
CVE-2021-35031: A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authent2021-12-28