CVE-2019-15802: Medium severity zyxel gs1900-8hp firmware vulnerability
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware hashes and encrypts passwords using a hardcoded cryptographic key in salutilstrencrypt() in libsal.so.0.0. The parameters (salt, IV, and key data) are used to encrypt and decrypt all passwords using AES256 in CBC mode. With the parameters known, all previously encrypted passwords can be decrypted. This includes the passwords that are part of configuration backups or otherwise embedded as part of the firmware.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-15802?
CVE-2019-15802 is a vulnerability found on Zyxel GS1900 devices that allows attackers to decrypt user passwords.
What is the severity of CVE-2019-15802?
The severity of CVE-2019-15802 is medium with a CVSS score of 5.9.
How can attackers exploit CVE-2019-15802?
Attackers can exploit CVE-2019-15802 by decrypting user passwords and gaining unauthorized access to the affected Zyxel GS1900 devices.
How can I fix CVE-2019-15802?
To fix CVE-2019-15802, update your Zyxel GS1900 device firmware to version 2.50(AAHH.0)C0 or later, as provided by Zyxel.
Where can I find more information about CVE-2019-15802?
You can find more information about CVE-2019-15802 in the following references: [link 1](https://jasper.la/exploring-zyxel-gs1900-firmware-with-ghidra.html), [link 2](https://www.zyxel.com/support/gs1900-switch-vulnerabilities.shtml).