Cryptographic Vulnerability in Zyxel GS1900 Devices
CVE-2019-15801
7.5HIGH
What is CVE-2019-15801?
A security issue was found in Zyxel GS1900 devices running firmware versions earlier than 2.50(AAHH.0)C0. The firmware incorporates encrypted passwords for user authentication to access diagnostic and password recovery menus. However, through the use of a hardcoded cryptographic key embedded within the firmware, these passwords can be decrypted, leading to potential unauthorized access. This flaw is tied to the functions fds_sys_passDebugPasswd_ret() and fds_sys_passRecoveryPasswd_ret() found in libfds.so.0.0.