Home

Description

A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0, GS1200-8v3 firmware versions through 1.00(ACPT.2)C0, GS1200-5HPv3 firmware versions through 1.00(ACPU.2)C0, GS1200-8HPv3 firmware versions through 1.00(ACPV.2)C0, and GS1200-10v3 firmware versions through 1.00(ACPW.2)C0 could allow a LAN-based, unauthenticated attacker to read the system configuration from a log file via a crafted HTTP request.

PUBLISHED Reserved 2026-03-25 | Published 2026-05-26 | Updated 2026-05-26 | Assigner Zyxel




MEDIUM: 6.5CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Problem types

CWE-862: Missing Authorization

Product status

Default status
unaffected

<= 1.00(ACPS.2)C0
affected

Default status
unaffected

<= 1.00(ACPT.2)C0
affected

Default status
unaffected

<= 1.00(ACPU.2)C0
affected

Default status
unaffected

<= 1.00(ACPV.2)C0
affected

Default status
unaffected

<= 1.00(ACPW.2)C0
affected

References

www.zyxel.com/...lity-in-gs1200v3-series-switches-05-26-2026 vendor-advisory

cve.org (CVE-2026-4795)

nvd.nist.gov (CVE-2026-4795)

Download JSON