Description
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Through an undocumented sequence of keypresses, undocumented functionality is triggered. A diagnostics shell is triggered via CTRL-ALT-t, which prompts for the password returned by fds_sys_passDebugPasswd_ret(). The firmware contains access control checks that determine if remote users are allowed to access this functionality. The function that performs this check (fds_sys_remoteDebugEnable_ret in libfds.so) always return TRUE with no actual checks performed. The diagnostics menu allows for reading/writing arbitrary registers and various other configuration parameters which are believed to be related to the network interface chips.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-6722 | An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Through an undocumented sequence of keypresses, undocumented functionality is triggered. A diagnostics shell is triggered via CTRL-ALT-t, which prompts for the password returned by fds_sys_passDebugPasswd_ret(). The firmware contains access control checks that determine if remote users are allowed to access this functionality. The function that performs this check (fds_sys_remoteDebugEnable_ret in libfds.so) always return TRUE with no actual checks performed. The diagnostics menu allows for reading/writing arbitrary registers and various other configuration parameters which are believed to be related to the network interface chips. |
References
History
No history.
Subscriptions
Zyxel
Subscribe
Gs1900-10hp
Subscribe
Gs1900-10hp Firmware
Subscribe
Gs1900-16
Subscribe
Gs1900-16 Firmware
Subscribe
Gs1900-24
Subscribe
Gs1900-24 Firmware
Subscribe
Gs1900-24e
Subscribe
Gs1900-24e Firmware
Subscribe
Gs1900-24hp
Subscribe
Gs1900-24hp Firmware
Subscribe
Gs1900-48
Subscribe
Gs1900-48 Firmware
Subscribe
Gs1900-48hp
Subscribe
Gs1900-48hp Firmware
Subscribe
Gs1900-8
Subscribe
Gs1900-8 Firmware
Subscribe
Gs1900-8hp
Subscribe
Gs1900-8hp Firmware
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T00:56:22.468Z
Reserved: 2019-08-29T00:00:00.000Z
Link: CVE-2019-15803
No data.
Status : Modified
Published: 2019-11-14T21:15:11.890
Modified: 2024-11-21T04:29:29.943
Link: CVE-2019-15803
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD