Vulnerability Intelligence Report
CVE-2022-45853
The privilege escalation vulnerability in the Zyxel GS1900-8 firmware version V2.70(AAHH.3) and the GS1900-8HP firmware version V2.70(AAHI.3) could allow an authenticated, local attacker with administrator privileges to execute some system commands as 'root' on a vulnerable device via SSH.
No Active Exploit Signals
CVSS Base Score
6.7
MEDIUM
Exploitability:0.8
Impact Score:5.9
EPSS Probability:0.17%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-269 ↗CWE-269 Improper Privilege Management
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Zyxel | GS1900-8HP firmware | V2.70(AAHI.3) (affected) |
| Zyxel | GS1900-8 firmware | V2.70(AAHH.3) (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.170%
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Zyxel Corporation · Vendor · Taiwan |
| Reserved | 2022-11-23T08:05:40 |
| Published | 2023-05-30T10:02:46 |
| Last Updated | 2025-01-10T17:32:54 |
Community Chatter & Buzz