Vulnerability Details CVE-2021-35030
A vulnerability was found in the CGI program in Zyxel GS1900-8 firmware version V2.60, that did not properly sterilize packet contents and could allow an authenticated, local user to perform a cross-site scripting (XSS) attack via a crafted LLDP packet.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 31.6%
CVSS Severity
CVSS v3 Score 3.5
CVSS v2 Score 2.3
Products affected by CVE-2021-35030
-
cpe:2.3:h:zyxel:gs1900-10hp:-
-
cpe:2.3:h:zyxel:gs1900-16:-
-
cpe:2.3:h:zyxel:gs1900-24:-
-
cpe:2.3:h:zyxel:gs1900-24e:-
-
cpe:2.3:h:zyxel:gs1900-24ep:-
-
cpe:2.3:h:zyxel:gs1900-24hp:-
-
cpe:2.3:h:zyxel:gs1900-24hpv2:-
-
cpe:2.3:h:zyxel:gs1900-48:-
-
cpe:2.3:h:zyxel:gs1900-48hp:-
-
cpe:2.3:h:zyxel:gs1900-48hpv2:-
-
cpe:2.3:h:zyxel:gs1900-8:-
-
cpe:2.3:h:zyxel:gs1900-8hp:-
-
cpe:2.3:o:zyxel:gs1900-10hp_firmware:-
-
cpe:2.3:o:zyxel:gs1900-10hp_firmware:2.40
-
cpe:2.3:o:zyxel:gs1900-10hp_firmware:2.50(aazi.0)c0
-
cpe:2.3:o:zyxel:gs1900-16_firmware:-
-
cpe:2.3:o:zyxel:gs1900-16_firmware:2.40
-
cpe:2.3:o:zyxel:gs1900-16_firmware:2.50(aahj.0)c0
-
cpe:2.3:o:zyxel:gs1900-24_firmware:-
-
cpe:2.3:o:zyxel:gs1900-24_firmware:2.40
-
cpe:2.3:o:zyxel:gs1900-24_firmware:2.50(aahl.0)c0
-
cpe:2.3:o:zyxel:gs1900-24e_firmware:-
-
cpe:2.3:o:zyxel:gs1900-24e_firmware:2.40
-
cpe:2.3:o:zyxel:gs1900-24e_firmware:2.50(aahk.0)c0
-
cpe:2.3:o:zyxel:gs1900-24ep_firmware:*
-
cpe:2.3:o:zyxel:gs1900-24hp_firmware:-
-
cpe:2.3:o:zyxel:gs1900-24hp_firmware:2.40
-
cpe:2.3:o:zyxel:gs1900-24hp_firmware:2.50(aahm.0)c0
-
cpe:2.3:o:zyxel:gs1900-24hpv2_firmware:*
-
cpe:2.3:o:zyxel:gs1900-48_firmware:-
-
cpe:2.3:o:zyxel:gs1900-48_firmware:2.40
-
cpe:2.3:o:zyxel:gs1900-48_firmware:2.50(aahn.0)c0
-
cpe:2.3:o:zyxel:gs1900-48hp_firmware:-
-
cpe:2.3:o:zyxel:gs1900-48hp_firmware:2.40
-
cpe:2.3:o:zyxel:gs1900-48hp_firmware:2.50(aaho.0)c0
-
cpe:2.3:o:zyxel:gs1900-48hpv2_firmware:*
-
cpe:2.3:o:zyxel:gs1900-8_firmware:-
-
cpe:2.3:o:zyxel:gs1900-8_firmware:2.40
-
cpe:2.3:o:zyxel:gs1900-8_firmware:2.50(aaho.0)c0
-
cpe:2.3:o:zyxel:gs1900-8hp_firmware:-
-
cpe:2.3:o:zyxel:gs1900-8hp_firmware:2.40
-
cpe:2.3:o:zyxel:gs1900-8hp_firmware:2.50(aahi.0)c0