CVE-2026-4795

MEDIUM

Zyxel GS1200-5v3 Firmware - Missing Authorization

Title source: rule
STIX 2.1

Description

A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0, GS1200-8v3 firmware versions through 1.00(ACPT.2)C0,  GS1200-5HPv3 firmware versions through 1.00(ACPU.2)C0, GS1200-8HPv3 firmware versions through 1.00(ACPV.2)C0, and GS1200-10v3 firmware versions through 1.00(ACPW.2)C0 could allow a LAN-based, unauthenticated attacker to read the system configuration from a log file via a crafted HTTP request.

Scores

CVSS v3 6.5
EPSS 0.0023
EPSS Percentile 14.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (5)
Zyxel/GS1200-10v3 firmware <= 1.00(ACPW.2)C0
Zyxel/GS1200-5HPv3 firmware <= 1.00(ACPU.2)C0
Zyxel/GS1200-5v3 firmware <= 1.00(ACPS.2)C0
Zyxel/GS1200-8HPv3 firmware <= 1.00(ACPV.2)C0
Zyxel/GS1200-8v3 firmware <= 1.00(ACPT.2)C0
Published May 26, 2026
Tracked Since May 26, 2026