CVE-2019-15801 affects Zyxel GS1900 series devices with firmware older than 2.50(AAHH.0)C0. The vulnerability stems from hardcoded, encrypted passwords within the firmware that grant access to diagnostic or password-recovery menus. Attackers can decrypt these passwords using a cryptographic key also present in the firmware, leading to unauthorized access. This high-severity vulnerability (CVSS 7.5) requires no user interaction or prior authentication, allowing remote attackers to achieve full confidentiality impact. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.50\(aahh.0\)c0CPE matchmatch criteria | cpe:2.3:o:zyxel:gs1900-8_firmware:*:*:*:*:*:*:*:* | ||
< 2.50\(aahi.0\)c0CPE matchmatch criteria | cpe:2.3:o:zyxel:gs1900-8hp_firmware:*:*:*:*:*:*:*:* | ||
< 2.50\(aazi.0\)c0CPE matchmatch criteria | cpe:2.3:o:zyxel:gs1900-10hp_firmware:*:*:*:*:*:*:*:* | ||
< 2.50\(aahj.0\)c0CPE matchmatch criteria | cpe:2.3:o:zyxel:gs1900-16_firmware:*:*:*:*:*:*:*:* | ||
< 2.50\(aahk.0\)c0CPE matchmatch criteria | cpe:2.3:o:zyxel:gs1900-24e_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.