CVE-2021-35032: OS Command Injection
Published Dec 28, 2021
·Updated
A vulnerability in the 'libsal.so' of the Zyxel GS1900 series firmware version 2.60 could allow an authenticated local user to execute arbitrary OS commands via a crafted function call.
Affected Software
24 affected components
Zyxel GS1900-8 firmware<2.70\(aahh.0\)-20211208
Zyxel GS1900-8
Zyxel GS1900-8HP firmware<2.70\(aahi.0\)-20211208
Zyxel GS1900-8HP
Zyxel GS1900-10HP firmware<2.70\(aazi.0\)-20211208
Zyxel GS1900-10HP
Zyxel Gs1900-16 Firmware<2.70\(aahj.0\)-20211208
Zyxel Gs1900-16
Zyxel Gs1900-24e Firmware<2.70\(aahk.0\)-20211208
Zyxel GS1900-24E
Zyxel Gs1900-24ep Firmware<2.70\(abto.0\)-20211208
Zyxel GS1900-24EP
Zyxel Gs1900-24 Firmware<2.70\(aahl.0\)-20211208
Zyxel GS1900-24
Zyxel Gs1900-24hp Firmware<2.70\(aahm.0\)-20211208
Zyxel Gs1900-24hp
Zyxel Gs1900-24hpv2 Firmware<2.70\(aatp.0\)-20211208
Zyxel Gs1900-24hpv2
Zyxel Gs1900-48 Firmware<2.70\(aahn.0\)-20211208
Zyxel GS1900-48
Zyxel Gs1900-48hp Firmware<2.70\(aaho.0\)-20211208
Zyxel Gs1900-48hp
Zyxel Gs1900-48hpv2 Firmware<2.70\(abtq.0\)-20211208
Zyxel Gs1900-48hpv2
Remediation
Event History
Dec 28, 2021
CVE Published
via MITRE·10:42 AM
Data Sourced
via MITRE·10:42 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2021-35032
2
What is the severity of CVE-2021-35032?
The severity of CVE-2021-35032 is high (7.8)
3
Which products are affected by CVE-2021-35032?
The Zyxel GS1900 series firmware version 2.60 is affected by CVE-2021-35032.
4
How can an attacker exploit CVE-2021-35032?
An authenticated local user can exploit CVE-2021-35032 by executing arbitrary OS commands via a crafted function call.
5
Is there a fix available for CVE-2021-35032?
Yes, Zyxel has released a firmware update to address the vulnerability. Please refer to the Zyxel security advisory for more information.