Undocumented Functionality in Zyxel GS1900 Devices Due to CLI Signal Flaw
CVE-2019-15804
7.5HIGH
What is CVE-2019-15804?
A security concern has been identified in Zyxel GS1900 devices running firmware prior to 2.50(AAHH.0)C0, which allows unauthorized access to a hidden menu through a SIGQUIT signal sent to the Command Line Interface (CLI). This menu includes options for password recovery for specific users but is intended to be restricted. The access check for this menu is not effectively enforced, particularly when accessed via a serial console, raising significant risk for potential unauthorized operations and device manipulation.