CVE-2026-4795
Zyxel GS1200 Series Firmware Missing Authorization Information Disclosure
Record summary
CVE-2026-4795 has a selected CVSS score of 6.5 (medium).
Description
A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0, GS1200-8v3 firmware versions through 1.00(ACPT.2)C0, GS1200-5HPv3 firmware versions through 1.00(ACPU.2)C0, GS1200-8HPv3 firmware versions through 1.00(ACPV.2)C0, and GS1200-10v3 firmware versions through 1.00(ACPW.2)C0 could allow a LAN-based, unauthenticated attacker to read the system configuration from a log file via a crafted HTTP request.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 26, 2026 · Source: CVE List
Affected products and versions
5| Product | Source | Version range | Status |
|---|---|---|---|
GS1200-10v3 firmwareBrowse Zyxel / GS1200-10v3 firmwareDefault status: unaffected | CVE List | <= 1.00(ACPW.2)C0 | affected |
GS1200-5HPv3 firmwareBrowse Zyxel / GS1200-5HPv3 firmwareDefault status: unaffected | CVE List | <= 1.00(ACPU.2)C0 | affected |
GS1200-5v3 firmwareBrowse Zyxel / GS1200-5v3 firmwareDefault status: unaffected | CVE List | <= 1.00(ACPS.2)C0 | affected |
GS1200-8HPv3 firmwareBrowse Zyxel / GS1200-8HPv3 firmwareDefault status: unaffected | CVE List | <= 1.00(ACPV.2)C0 | affected |
GS1200-8v3 firmwareBrowse Zyxel / GS1200-8v3 firmwareDefault status: unaffected | CVE List | <= 1.00(ACPT.2)C0 | affected |