CVE-2024-8881: OS Command Injection
A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with administrator privileges to execute some operating system (OS) commands on an affected device by sending a crafted HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8881?
CVE-2024-8881 is classified as a high-severity vulnerability due to its potential impact on affected devices.
How do I fix CVE-2024-8881?
To mitigate CVE-2024-8881, upgrade the Zyxel GS1900-48 switch firmware to version 2.90(AAHN.0)C0 or later.
Who can exploit CVE-2024-8881?
CVE-2024-8881 can be exploited by an authenticated LAN-based attacker with administrator privileges.
What type of vulnerability is CVE-2024-8881?
CVE-2024-8881 is a post-authentication command injection vulnerability affecting CyXEL GS1900 series switches.
Which devices are affected by CVE-2024-8881?
The devices affected by CVE-2024-8881 include Zyxel GS1900-48 switches running firmware version V2.80(AAHN.1)C0 or earlier.