Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-35029


An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.


Published

2021-07-02T11:15:08.930

Last Modified

2024-11-21T06:11:42.280

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-287
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System zyxel usg1900_firmware ≤ 4.64 Yes
Hardware zyxel usg1900 - No
Operating System zyxel usg1100_firmware ≤ 4.64 Yes
Hardware zyxel usg1100 - No
Operating System zyxel usg310_firmware ≤ 4.64 Yes
Hardware zyxel usg310 - No
Operating System zyxel usg210_firmware ≤ 4.64 Yes
Hardware zyxel usg210 - No
Operating System zyxel usg110_firmware ≤ 4.64 Yes
Hardware zyxel usg110 - No
Operating System zyxel usg40_firmware ≤ 4.64 Yes
Hardware zyxel usg40 - No
Operating System zyxel usg40w_firmware ≤ 4.64 Yes
Hardware zyxel usg40w - No
Operating System zyxel usg60_firmware ≤ 4.64 Yes
Hardware zyxel usg60 - No
Operating System zyxel usg60w_firmware ≤ 4.64 Yes
Hardware zyxel usg60w - No
Operating System zyxel usg300_firmware ≤ 4.64 Yes
Hardware zyxel usg300 - No
Operating System zyxel usg1000_firmware ≤ 4.64 Yes
Hardware zyxel usg1000 - No
Operating System zyxel usg2000_firmware ≤ 4.64 Yes
Hardware zyxel usg2000 - No
Operating System zyxel usg20_firmware ≤ 4.64 Yes
Hardware zyxel usg20 - No
Operating System zyxel usg20w_firmware ≤ 4.64 Yes
Hardware zyxel usg20w - No
Operating System zyxel usg50_firmware ≤ 4.64 Yes
Hardware zyxel usg50 - No
Operating System zyxel usg100_firmware ≤ 4.64 Yes
Hardware zyxel usg100 - No
Operating System zyxel usg200_firmware ≤ 4.64 Yes
Hardware zyxel usg200 - No
Operating System zyxel usg_flex_100_firmware ≤ 5.01 Yes
Hardware zyxel usg_flex_100 - No
Operating System zyxel usg_flex_200_firmware ≤ 5.01 Yes
Hardware zyxel usg_flex_200 - No
Operating System zyxel usg_flex_500_firmware ≤ 5.01 Yes
Hardware zyxel usg_flex_500 - No
Operating System zyxel usg_flex_100w_firmware ≤ 5.01 Yes
Hardware zyxel usg_flex_100w - No
Operating System zyxel usg_flex_700_firmware ≤ 5.01 Yes
Hardware zyxel usg_flex_700 - No
Operating System zyxel zywall_atp100_firmware ≤ 5.01 Yes
Hardware zyxel zywall_atp100 - No
Operating System zyxel zywall_atp100w_firmware ≤ 5.01 Yes
Hardware zyxel zywall_atp100w - No
Operating System zyxel zywall_atp200_firmware ≤ 5.01 Yes
Hardware zyxel zywall_atp200 - No
Operating System zyxel zywall_atp500_firmware ≤ 5.01 Yes
Hardware zyxel zywall_atp500 - No
Operating System zyxel zywall_atp700_firmware ≤ 5.01 Yes
Hardware zyxel zywall_atp700 - No
Operating System zyxel zywall_atp800_firmware ≤ 5.01 Yes
Hardware zyxel zywall_atp800 - No
Operating System zyxel zywall_vpn50_firmware ≤ 5.01 Yes
Hardware zyxel zywall_vpn50 - No
Operating System zyxel zywall_vpn100_firmware ≤ 5.01 Yes
Hardware zyxel zywall_vpn100 - No
Operating System zyxel zywall_vpn300_firmware ≤ 5.01 Yes
Hardware zyxel zywall_vpn300 - No
Operating System zyxel usg20-vpn_firmware ≤ 5.01 Yes
Hardware zyxel usg20-vpn - No
Operating System zyxel usg20w-vpn_firmware ≤ 5.01 Yes
Hardware zyxel usg20w-vpn - No
Operating System zyxel usg2200-vpn_firmware ≤ 5.01 Yes
Hardware zyxel usg2200-vpn - No
Operating System zyxel zywall_110_firmware ≤ 5.01 Yes
Hardware zyxel zywall_110 - No
Operating System zyxel zywall_310_firmware ≤ 5.01 Yes
Hardware zyxel zywall_310 - No
Operating System zyxel zywall_1100_firmware ≤ 5.01 Yes
Hardware zyxel zywall_1100 - No

References