Vulnerability record · CVE-2019-15800 · published 14 November 2019
CVE-2019-15800: Zyxel gs1900-8 firmware os command injection vulnerability
Zyxel · Gs1900 8 Firmware
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in the cmd_sys_traceroute_exec(), cmd_sys_arp_clear(), and cmd_sys_ping_exec() functions in the libclicmd.so library contained in the firmware, an attacker could leverage these functions to call system() and execute arbitrary commands on the switches. (Note that these functions are currently not called in this version of the firmware, however an attacker could use other vulnerabilities to finally use these vulnerabilities to gain code execution.)
Description
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in the cmd_sys_traceroute_exec(), cmd_sys_arp_clear(), and cmd_sys_ping_exec() functions in the libclicmd.so library contained in the firmware, an attacker could leverage these functions to call system() and execute arbitrary commands on the switches. (Note that these functions are currently not called in this version of the firmware, however an attacker could use other vulnerabilities to finally use these vulnerabilities to gain code execution.)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://jasper.la/exploring-zyxel-gs1900-firmware-with-ghidra.html | ExploitThird Party Advisory |
| https://www.zyxel.com/support/gs1900-switch-vulnerabilities.shtml | Vendor Advisory |
| https://jasper.la/exploring-zyxel-gs1900-firmware-with-ghidra.html | ExploitThird Party Advisory |
| https://www.zyxel.com/support/gs1900-switch-vulnerabilities.shtml | Vendor Advisory |
Track CVE-2019-15800 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-15800), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.