- EPSS 3.08%
- Published 14.11.2019 21:15:11
- Last modified 21.11.2024 04:29:29
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in the cmd_sys_traceroute_exec(), cmd_sys_arp_clear(), and cmd_sys_ping_exec() functions in the libclicmd.so library contained in the...
CVE-2019-15801
- EPSS 0.29%
- Published 14.11.2019 21:15:11
- Last modified 21.11.2024 04:29:29
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware image contains encrypted passwords that are used to authenticate users wishing to access a diagnostics or password-recovery menu. Using the hardcoded cr...
CVE-2019-15802
- EPSS 0.29%
- Published 14.11.2019 21:15:11
- Last modified 21.11.2024 04:29:29
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware hashes and encrypts passwords using a hardcoded cryptographic key in sal_util_str_encrypt() in libsal.so.0.0. The parameters (salt, IV, and key data) ar...
CVE-2019-15803
- EPSS 0.38%
- Published 14.11.2019 21:15:11
- Last modified 21.11.2024 04:29:29
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Through an undocumented sequence of keypresses, undocumented functionality is triggered. A diagnostics shell is triggered via CTRL-ALT-t, which prompts for the passw...
CVE-2019-15804
- EPSS 0.24%
- Published 14.11.2019 21:15:11
- Last modified 21.11.2024 04:29:30
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. By sending a signal to the CLI process, undocumented functionality is triggered. Specifically, a menu can be triggered by sending the SIGQUIT signal to the CLI appli...