Impact
The vulnerability is a stack‑based buffer overflow in the CGI program of Zyxel GS1900 switches. An attacker on the same local network can exploit this flaw by sending a crafted HTTP request, potentially causing the switch to execute operating‑system commands. This could lead to full control over the device’s operating system.
Affected Systems
Affected devices include Zyxel GS1900‑8, GS1900‑8HP, GS1900‑10HP, GS1900‑16, GS1900‑24, GS1900‑24E, GS1900‑24EP, GS1900‑24HPv2, GS1900‑48, and GS1900‑48HPv2 firmware versions up through and including 2.90(ABTQ.1)C0.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of 1% suggests a low probability of exploitation at present. It is listed in CISA’s KEV catalog. Exploitation requires an unauthenticated connection from a device on the same local network that can reach the switch’s HTTP management interface, after which the attacker could run arbitrary OS commands on the device.
OpenCVE Enrichment