Junglewise Threat Intelligence

CVE-2026-4795: Zyxel GS1200v3 series missing authorization in log files

CVE-2026-4795 · Severity: medium · CVSS 6.5 · Published 2026-05-26

Vendors: Zyxel.

Executive brief

A security vulnerability has been identified in several Zyxel GS1200 series network switches, which are used to manage data traffic in small to medium-sized offices. An unauthorized person on the local network could exploit this flaw to access sensitive system configuration files. This could lead to the exposure of network settings and other administrative information, potentially helping an attacker plan further intrusions.

Technical details

A missing authorization vulnerability (CWE-862) exists in the firmware of Zyxel GS1200v3 series switches. The flaw allows an unauthenticated attacker with adjacent network access (LAN-based) to retrieve system configuration information by sending a specifically crafted HTTP request to access log files. This occurs because the device fails to properly restrict access to sensitive files containing configuration data. Successful exploitation results in high confidentiality impact as it exposes the device's internal settings. Zyxel has released firmware updates (v1.00(ACPS.3)C0 through v1.00(ACPW.3)C0 depending on the model) to address this issue.

Affected products

  • Zyxel GS1200-5v3 through 1.00(ACPS.2)C0
  • Zyxel GS1200-8v3 through 1.00(ACPT.2)C0
  • Zyxel GS1200-5HPv3 through 1.00(ACPU.2)C0
  • Zyxel GS1200-8HPv3 through 1.00(ACPV.2)C0
  • Zyxel GS1200-10v3 through 1.00(ACPW.2)C0

Timeline

  • 2026-05-26: disclosed: Initial release of the security advisory by Zyxel.
  • 2026-05-26: patched: Firmware patches released for all affected models.

References