NewStart CGSL MAIN 7.02 : openssh Multiple Vulnerabilities (NS-SA-2026-0101)

critical Nessus Plugin ID 343592

Synopsis

The remote NewStart CGSL host is affected by multiple vulnerabilities.

Description

The remote NewStart CGSL host, running version MAIN 7.02, has openssh packages installed that are affected by multiple vulnerabilities:

- ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re- exchange. (This outcome occurs only on the client side.) (CVE-2026-60002)

- In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without
-p (preserve mode). (CVE-2026-35385)

- In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config. (CVE-2026-35386)

- OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms.
(CVE-2026-35387)

- OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
(CVE-2026-35388)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the vulnerable CGSL openssh packages. Note that updated packages may not be available yet. Please contact ZTE for more information.

See Also

https://security.gd-linux.com/info/CVE-2026-35385

https://security.gd-linux.com/info/CVE-2026-35386

https://security.gd-linux.com/info/CVE-2026-35387

https://security.gd-linux.com/info/CVE-2026-35388

https://security.gd-linux.com/info/CVE-2026-59995

https://security.gd-linux.com/info/CVE-2026-59996

https://security.gd-linux.com/info/CVE-2026-59997

https://security.gd-linux.com/info/CVE-2026-59999

https://security.gd-linux.com/info/CVE-2026-60000

https://security.gd-linux.com/info/CVE-2026-60001

https://security.gd-linux.com/info/CVE-2026-60002

https://security.gd-linux.com/notice/NS-SA-2026-0101

Plugin Details

Severity: Critical

ID: 343592

File Name: newstart_cgsl_NS-SA-2026-0101_openssh.nasl

Version: 1.1

Type: Local

Published: 9/8/2026

Updated: 9/8/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.97

CVSS v2

Risk Factor: High

Base Score: 9.7

Temporal Score: 7.2

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:P

CVSS Score Source: CVE-2026-60002

CVSS v3

Risk Factor: Critical

Base Score: 9.4

Temporal Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:zte:cgsl_main:7, p-cpe:/a:zte:cgsl_main:openssh-api, p-cpe:/a:zte:cgsl_main:openssh-askpass, p-cpe:/a:zte:cgsl_main:openssh-clients-core, p-cpe:/a:zte:cgsl_main:openssh-clients, p-cpe:/a:zte:cgsl_main:openssh-core, p-cpe:/a:zte:cgsl_main:openssh-doc, p-cpe:/a:zte:cgsl_main:openssh-keycat, p-cpe:/a:zte:cgsl_main:openssh-server-core, p-cpe:/a:zte:cgsl_main:openssh-server, p-cpe:/a:zte:cgsl_main:openssh-sk-dummy, p-cpe:/a:zte:cgsl_main:openssh

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/ZTE-CGSL/release, Host/ZTE-CGSL/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 9/7/2026

Vulnerability Publication Date: 4/2/2026

Reference Information

CVE: CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, CVE-2026-60002

IAVA: 2026-A-0296-S, 2026-A-0691-S