CVE-2024-8882
MEDIUMDescription
A buffer overflow vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with administrator privileges to cause denial of service (DoS) conditions via a crafted URL.
Is your site exposed to CVE-2024-8882?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| zyxel | gs1900-8_firmware |
| zyxel | gs1900-8 |
| zyxel | gs1900-8hp_firmware |
| zyxel | gs1900-8hp |
| zyxel | gs1900-10hp_firmware |
| zyxel | gs1900-10hp |
| zyxel | gs1900-16_firmware |
| zyxel | gs1900-16 |
| zyxel | gs1900-24_firmware |
| zyxel | gs1900-24 |
| zyxel | gs1900-24e_firmware |
| zyxel | gs1900-24e |
| zyxel | gs1900-24ep_firmware |
| zyxel | gs1900-24ep |
| zyxel | gs1900-24hpv2_firmware |
| zyxel | gs1900-24hpv2 |
| zyxel | gs1900-48_firmware |
| zyxel | gs1900-48 |
| zyxel | gs1900-48hpv2_firmware |
| zyxel | gs1900-48hpv2 |
References
Frequently Asked Questions
What is CVE-2024-8882? +
How severe is CVE-2024-8882? +
What products are affected by CVE-2024-8882? +
How do I check if I'm vulnerable to CVE-2024-8882? +
Related Vulnerabilities
zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain …
A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a malicious …
A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious user to write invalid file data …
A denial-of-service issue exists in 5370/5570 controllers. This vulnerability could potentially allow a remote user to load an invalid project, …
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Newtec NTC2218, NTC2250, NTC2299 on Linux, PowerPC, ARM …
An unauthenticated attacker on the WAN interface, with the ability to intercept Dynamic DNS (DDNS) traffic between DDNS services and …