{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-01T21:33:13.206","vulnerabilities":[{"cve":{"id":"CVE-2021-35030","sourceIdentifier":"security@zyxel.com.tw","published":"2021-07-26T12:15:08.817","lastModified":"2026-06-17T03:56:58.623","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was found in the CGI program in Zyxel GS1900-8 firmware version V2.60, that did not properly sterilize packet contents and could allow an authenticated, local user to perform a cross-site scripting (XSS) attack via a crafted LLDP packet."},{"lang":"es","value":"Se ha encontrado una vulnerabilidad en el programa CGI de Zyxel GS1900-8 versión del firmware V2.60, que no esterilizaba apropiadamente el contenido de los paquetes y podía permitir a un usuario local autenticado llevar a cabo un ataque de tipo cross-site scripting (XSS) por medio de un paquete LLDP diseñado"}],"affected":[{"source":"security@zyxel.com.tw","affectedData":[{"vendor":"Zyxel","product":"GS1900-8 Firmware","versions":[{"version":"2.60","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@zyxel.com.tw","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L","baseScore":3.5,"baseSeverity":"LOW","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":0.9,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:A/AC:M/Au:S/C:N/I:P/A:N","baseScore":2.3,"accessVector":"ADJACENT_NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":4.4,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"security@zyxel.com.tw","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:gs1900-8_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.70","matchCriteriaId":"AD447145-9B13-4B3E-B35E-65AB4A576B8D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:gs1900-8:-:*:*:*:*:*:*:*","matchCriteriaId":"51D33F50-B5A4-4AEF-972C-7FF089C21D52"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:gs1900-8hp_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.70","matchCriteriaId":"06D9347D-F0F3-4E9B-8EF6-AA2A723A55E6"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:gs1900-8hp:-:*:*:*:*:*:*:*","matchCriteriaId":"27602862-EFB7-402B-994E-254A0B210820"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:gs1900-10hp_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.70","matchCriteriaId":"A54B9C24-6492-463F-8768-BF1E092D9077"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:gs1900-10hp:-:*:*:*:*:*:*:*","matchCriteriaId":"89201505-07AF-4F9C-9304-46F2707DB9B4"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:gs1900-16_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.70","matchCriteriaId":"9D2B2385-9DDF-4E5E-9CFE-12B0304568BF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:gs1900-16:-:*:*:*:*:*:*:*","matchCriteriaId":"5078F7A5-D03B-4D3A-9C19-57DFF4D6BF7A"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:gs1900-24e_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.70","matchCriteriaId":"674594F8-B90F-4D8E-82E4-9DE721BC52E5"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:gs1900-24e:-:*:*:*:*:*:*:*","matchCriteriaId":"A6456AD6-8A1D-4D3D-AC1A-ABE442242B1B"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:gs1900-24ep_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.70","matchCriteriaId":"F69D2726-44BB-4AFB-9447-2220675020AE"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:gs1900-24ep:-:*:*:*:*:*:*:*","matchCriteriaId":"B22AA8B1-11E2-408F-A1F6-0F8AF32AB131"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:gs1900-24_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.70","matchCriteriaId":"FC29ADFF-27E6-4CFA-8C5F-32542AC36052"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:gs1900-24:-:*:*:*:*:*:*:*","matchCriteriaId":"F4F55299-70D5-4CE1-A1EC-D79B469B94F7"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:gs1900-24hp_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.70","matchCriteriaId":"4567A0DB-6E8E-4714-B573-8FEA4A571738"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:gs1900-24hp:-:*:*:*:*:*:*:*","matchCriteriaId":"74B1D264-99AC-4AA8-955C-602F2DA5B885"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:gs1900-24hpv2_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.70","matchCriteriaId":"99DCDB75-4D17-4A05-AF5A-4ADA54A54142"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:gs1900-24hpv2:-:*:*:*:*:*:*:*","matchCriteriaId":"512D9A91-8DA7-47F1-AC77-AF743F99BFF3"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:gs1900-48_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.70","matchCriteriaId":"BD68BF23-59DC-4449-9B53-ACBCC6F4A871"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:gs1900-48:-:*:*:*:*:*:*:*","matchCriteriaId":"CFB7D4BF-7D17-48D3-990D-4BADAC8BD868"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:gs1900-48hp_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.70","matchCriteriaId":"0A4D35C7-255C-4842-8D75-22CAC3E14C6C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:gs1900-48hp:-:*:*:*:*:*:*:*","matchCriteriaId":"566A9E8C-AF55-4331-B9B0-F65EB900B0BE"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:gs1900-48hpv2_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.70","matchCriteriaId":"39C45C13-DD78-4486-833A-773A5F0A77A8"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:gs1900-48hpv2:-:*:*:*:*:*:*:*","matchCriteriaId":"BC74C679-6D22-47E4-AE8A-2647B1AA4276"}]}]}],"references":[{"url":"https://www.zyxel.com/support/Zyxel_security_advisory_for_XSS_vulnerability_of_GS1900_series_switches.shtml","source":"security@zyxel.com.tw","tags":["Patch","Vendor Advisory"]},{"url":"https://www.zyxel.com/support/Zyxel_security_advisory_for_XSS_vulnerability_of_GS1900_series_switches.shtml","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]}]}}]}