CVE-2023-35140: Zyxel GS1900-10hp Firmware

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

The improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could allow an authenticated local user with read-only access to modify system settings on a vulnerable device.

Affected products

  • Zyxel GS1900-10hp Firmware: up to and including 2.70\(aazi.5\)
  • Zyxel GS1900-16 Firmware: up to and including 2.70\(aahj.5\)
  • Zyxel GS1900-24 Firmware: up to and including 2.70\(aahl.5\)
  • Zyxel GS1900-24e Firmware: up to and including 2.70\(aahk.5\)
  • Zyxel GS1900-24ep Firmware: up to and including 2.70\(abto.5\)
  • Zyxel GS1900-24hpv2 Firmware: up to and including 2.70\(abtp.5\)
  • Zyxel GS1900-48 Firmware: up to and including 2.70\(aahn.5\)
  • Zyxel GS1900-48hpv2 Firmware: up to and including 2.70\(abtq.5\)
  • Zyxel GS1900-8 Firmware: up to and including 2.70\(aahh.5\)
  • Zyxel GS1900-8hp Firmware: up to and including 2.70\(aahi.5\)

Published 2023-11-07. Last modified 2026-06-17.