CVE-2024-8881
CVSS 3.1 Score 6.8 of 10 (medium)
Details
Summary
CVE-2024-8881 is a post-authentication command injection vulnerability affecting the CGI program in Zyxel GS1900-48 switch firmware versions V2.80(AAHN.1)C0 and earlier. An authenticated attacker with LAN access and administrator privileges can exploit this flaw to inject and execute OS commands on the affected device by sending a specially crafted HTTP request. Successful exploitation of this vulnerability could result in significant unintended consequences, including data theft or unauthorized control of the device. Organizations using Zyxel GS1900-48 switches with the affected firmware are advised to apply the available patch or upgrade to a newer version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- ZyXEL