SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-15804

An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0.

HIGH 7.5EPSS 0.93%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.93%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. By sending a signal to the CLI process, undocumented functionality is triggered. Specifically, a menu can be triggered by sending the SIGQUIT signal to the CLI application (e.g., through CTRL+\ via SSH). The access control check for this menu does work and prohibits accessing the menu, which contains "Password recovery for specific user" options. The menu is believed to be accessible using a serial console.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
0.93% probability · 59th percentile
CISA KEV
Not listed
Affected
zyxel/gs1900-8 firmware · zyxel/gs1900-8hp firmware · zyxel/gs1900-10hp firmware · zyxel/gs1900-16 firmware · zyxel/gs1900-24e firmware · zyxel/gs1900-24 firmware · zyxel/gs1900-24hp firmware · zyxel/gs1900-48 firmware · zyxel/gs1900-48hp firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.