Zyxel security advisory for XSS vulnerability of GS1900 series switches

Zyxel_Carter
Zyxel_Carter Posts: 41  Admin
edited August 2 in Security Advisories

CVE: CVE-2021-35030

Summary

Zyxel has released hotfixes addressing a cross-site scripting (XSS) vulnerability in the GS1900 series of switches and will include the patch in its next regular firmware update in October. Users are advised to install the applicable firmware updates for optimal protection.

What is the vulnerability?

A XSS vulnerability was identified in Zyxel’s GS1900 series of switches, such that an attack could be triggered when a user accesses certain GUI pages with the malicious LLDP packets processed by the switch. However, this can only occur if the attacker is directly connected to the switch, because the LLDP protocol only allows LLDP packets to be sent to and received from devices that are directly connected to each other; thus, the risk is relatively low.

What versions are vulnerable—and what should you do?

After a thorough investigation, we’ve identified the vulnerable switches that are within their warranty and support period and released firmware patches to address the issue, as shown in the table below.

Affected model

Patch availability

Hotfix
Standard firmware
GS1900-8
Link
V2.70 in Oct. 2021

GS1900-8HP

Link

V2.70 in Oct. 2021

GS1900-10HP
Link

V2.70 in Oct. 2021

GS1900-16
Link

V2.70 in Oct. 2021

GS1900-24E

Link

V2.70 in Oct. 2021

GS1900-24EP
Link

V2.70 in Oct. 2021

GS1900-24

Link
V2.70 in Oct. 2021
GS1900-24HP
Link
V2.70 in Oct. 2021

GS1900-24HPv2 

Link
V2.70 in Oct. 2021

GS1900-48 

Link
V2.70 in Oct. 2021

GS1900-48HP

Link
V2.70 in Oct. 2021

GS1900-48HPv2

Link
V2.70 in Oct. 2021


Got a question?

Please contact your local service rep or comment below for further information or assistance.

Acknowledgment

Thanks to Jasper Lievisse Adriaanse for reporting the issue to us.

Revision history

2021-7-27: Initial release

2021-7-30: Updated the hotfix links