### [CVE-2024-38270](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38270) ![](https://img.shields.io/static/v1?label=Product&message=GS1900-10HP%20firmware&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=V2.80(AAZI.0)C0%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-331%20Insufficient%20Entropy&color=brightgreen) ### Description An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2.80(AAZI.0)C0. This vulnerability could allow a LAN-based attacker a slight chance to gain a valid session token if multiple authenticated sessions are alive. ### POC #### Reference No PoCs from references. #### Github - https://github.com/fkie-cad/nvd-json-data-feeds