Vulnerability Description
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in the cmd_sys_traceroute_exec(), cmd_sys_arp_clear(), and cmd_sys_ping_exec() functions in the libclicmd.so library contained in the firmware, an attacker could leverage these functions to call system() and execute arbitrary commands on the switches. (Note that these functions are currently not called in this version of the firmware, however an attacker could use other vulnerabilities to finally use these vulnerabilities to gain code execution.)
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zyxel | Gs1900-8 Firmware | < 2.50\(aahh.0\)c0 |
| Zyxel | Gs1900-8 | - |
| Zyxel | Gs1900-8Hp Firmware | < 2.50\(aahi.0\)c0 |
| Zyxel | Gs1900-8Hp | - |
| Zyxel | Gs1900-10Hp Firmware | < 2.50\(aazi.0\)c0 |
| Zyxel | Gs1900-10Hp | - |
| Zyxel | Gs1900-16 Firmware | < 2.50\(aahj.0\)c0 |
| Zyxel | Gs1900-16 | - |
| Zyxel | Gs1900-24E Firmware | < 2.50\(aahk.0\)c0 |
| Zyxel | Gs1900-24E | - |
| Zyxel | Gs1900-24 Firmware | < 2.50\(aahl.0\)c0 |
| Zyxel | Gs1900-24 | - |
| Zyxel | Gs1900-24Hp Firmware | < 2.50\(aahm.0\)c0 |
| Zyxel | Gs1900-24Hp | - |
| Zyxel | Gs1900-48 Firmware | < 2.50\(aahn.0\)c0 |
| Zyxel | Gs1900-48 | - |
| Zyxel | Gs1900-48Hp Firmware | < 2.50\(aaho.0\)c0 |
| Zyxel | Gs1900-48Hp | - |
Related Weaknesses (CWE)
References
- https://jasper.la/exploring-zyxel-gs1900-firmware-with-ghidra.htmlExploitThird Party Advisory
- https://www.zyxel.com/support/gs1900-switch-vulnerabilities.shtmlVendor Advisory
- https://jasper.la/exploring-zyxel-gs1900-firmware-with-ghidra.htmlExploitThird Party Advisory
- https://www.zyxel.com/support/gs1900-switch-vulnerabilities.shtmlVendor Advisory
FAQ
What is CVE-2019-15800?
CVE-2019-15800 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in the cmd_sys_traceroute_exec(), cmd_sys_arp_clear(), and cmd_sys_ping_exec() func...
How severe is CVE-2019-15800?
CVE-2019-15800 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-15800?
Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Gs1900-8 Firmware, Zyxel Gs1900-8, Zyxel Gs1900-8Hp Firmware, Zyxel Gs1900-8Hp, Zyxel Gs1900-10Hp Firmware.