CVE-2021-35030

LOW

Zyxel GS1900 Series Firmware < 2.70 - Authenticated Cross-Site Scripting via LLDP Packet

Title source: llm
STIX 2.1

Description

A vulnerability was found in the CGI program in Zyxel GS1900-8 firmware version V2.60, that did not properly sterilize packet contents and could allow an authenticated, local user to perform a cross-site scripting (XSS) attack via a crafted LLDP packet.

References (1)

Core 1

Scores

CVSS v3 3.5
EPSS 0.0011
EPSS Percentile 29.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L

Details

CWE
CWE-79
Status published
Products (12)
zyxel/gs1900-10hp_firmware < 2.70
zyxel/gs1900-16_firmware < 2.70
zyxel/gs1900-24_firmware < 2.70
zyxel/gs1900-24e_firmware < 2.70
zyxel/gs1900-24ep_firmware < 2.70
zyxel/gs1900-24hp_firmware < 2.70
zyxel/gs1900-24hpv2_firmware < 2.70
zyxel/gs1900-48_firmware < 2.70
zyxel/gs1900-48hp_firmware < 2.70
zyxel/gs1900-48hpv2_firmware < 2.70
... and 2 more
Published Jul 26, 2021
Tracked Since Feb 18, 2026