Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Through an undocumented sequence of keypresses, undocumented functionality is triggered. A diagnostics shell is triggered via CTRL-ALT-t, which prompts for the password returned by fds_sys_passDebugPasswd_ret(). The firmware contains access control checks that determine if remote users are allowed to access this functionality. The function that performs this check (fds_sys_remoteDebugEnable_ret in libfds.so) always return TRUE with no actual checks performed. The diagnostics menu allows for reading/writing arbitrary registers and various other configuration parameters which are believed to be related to the network interface chips.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ZyXEL GS1900 输入验证错误漏洞
Vulnerability Description
ZyXEL GS1900是中国台湾合勤(ZyXEL)公司的一款管理型交换机。 使用2.50(AAHH.0)C0之前版本固件的Zyxel GS1900中存在安全漏洞。攻击者可利用该漏洞访问受限的功能。
CVSS Information
N/A
Vulnerability Type
N/A