CVE-2026-4795: Medium severity Zyxel GS1200-5v3 firmware vulnerability
A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0, GS1200-8v3 firmware versions through 1.00(ACPT.2)C0, GS1200-5HPv3 firmware versions through 1.00(ACPU.2)C0, GS1200-8HPv3 firmware versions through 1.00(ACPV.2)C0, and GS1200-10v3 firmware versions through 1.00(ACPW.2)C0 could allow a LAN-based, unauthenticated attacker to read the system configuration from a log file via a crafted HTTP request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zyxel GS1200-5v3to a version that resolves this vulnerability.Fixed in 1.00(ACPS.2)C0 - Upgrade
Upgrade
Zyxel GS1200-8v3to a version that resolves this vulnerability.Fixed in 1.00(ACPT.2)C0 - Upgrade
Upgrade
Zyxel GS1200-5HPv3to a version that resolves this vulnerability.Fixed in 1.00(ACPU.2)C0 - Upgrade
Upgrade
Zyxel GS1200-8HPv3to a version that resolves this vulnerability.Fixed in 1.00(ACPV.2)C0 - Upgrade
Upgrade
Zyxel GS1200-10v3to a version that resolves this vulnerability.Fixed in 1.00(ACPW.2)C0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4795?
The severity of CVE-2026-4795 is rated as medium with a score of 6.5.
What type of vulnerability is associated with CVE-2026-4795?
CVE-2026-4795 is a missing authorization vulnerability.
Which devices are affected by CVE-2026-4795?
CVE-2026-4795 affects Zyxel GS1200-5v3, GS1200-8v3, GS1200-5HPv3, GS1200-8HPv3, and GS1200-10v3 firmware versions.
How do I fix CVE-2026-4795?
To fix CVE-2026-4795, update the firmware of the affected Zyxel devices to the latest version provided by the vendor.
Is there a workaround for CVE-2026-4795?
There is no specific workaround for CVE-2026-4795; the best mitigation is to apply the firmware update.