CVE-2022-43393

HIGH

Zyxel GS1920-24v2 <V4.70(ABMH.8)C0 - Memory Corruption

Title source: llm
STIX 2.1

Description

An improper check for unusual or exceptional conditions in the HTTP request processing function of Zyxel GS1920-24v2 firmware prior to V4.70(ABMH.8)C0, which could allow an unauthenticated attacker to corrupt the contents of the memory and result in a denial-of-service (DoS) condition on a vulnerable device.

Scores

CVSS v3 8.2
EPSS 0.0135
EPSS Percentile 80.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-754
Status published
Products (47)
zyxel/gs1350-12hp_firmware < 4.70\(abpj.5\)c0
zyxel/gs1350-18hp_firmware < 4.70\(abpk.5\)c0
zyxel/gs1350-26hp_firmware < 4.70\(abpl.5\)c0
zyxel/gs1350-6hp_firmware < 4.70\(abpi.5\)c0
zyxel/gs1915-24e_firmware < 4.70\(acdr.3\)c0
zyxel/gs1915-24ep_firmware < 4.70\(acds.3\)c0
zyxel/gs1915-8_firmware < 4.70\(acap.3\)c0
zyxel/gs1915-8ep_firmware < 4.70\(acaq.3\)c0
zyxel/gs1920-24hpv2_firmware < 4.70\(abmi.8\)c0
zyxel/gs1920-24v2_firmware < 4.70\(abmh.8\)c0
... and 37 more
Published Jan 11, 2023
Tracked Since Feb 18, 2026