CVE-2024-38270: Zyxel GS1900-10hp Firmware
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2.80(AAZI.0)C0. This vulnerability could allow a LAN-based attacker a slight chance to gain a valid session token if multiple authenticated sessions are alive.
Affected products
- Zyxel GS1900-10hp Firmware: before 2.80\(aazi.1\)c0 (fixed in 2.80\(aazi.1\)c0)
- Zyxel GS1900-16 Firmware: before 2.80\(aahj.1\)c0 (fixed in 2.80\(aahj.1\)c0)
- Zyxel GS1900-24 Firmware: up to and including 2.80\(aahl.1\)c0
- Zyxel GS1900-24e Firmware: up to and including 2.80\(aahk.1\)c0
- Zyxel GS1900-24ep Firmware: before 2.80\(abto.1\)c0 (fixed in 2.80\(abto.1\)c0)
- Zyxel GS1900-24hpv2 Firmware: before 2.80\(abtp.1\)c0 (fixed in 2.80\(abtp.1\)c0)
- Zyxel GS1900-48 Firmware: before 2.80\(aahn.1\)c0 (fixed in 2.80\(aahn.1\)c0)
- Zyxel GS1900-48hpv2 Firmware: before 2.80\(abtq.1\)c0 (fixed in 2.80\(abtq.1\)c0)
- Zyxel GS1900-8 Firmware: before 2.80\(aahh.1\)c0 (fixed in 2.80\(aahh.1\)c0)
- Zyxel GS1900-8hp Firmware: before 2.80\(aahi.1\)c0 (fixed in 2.80\(aahi.1\)c0)
Published 2024-09-10. Last modified 2026-06-17.