Description
An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.
Published: 2021-07-02
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-21676 An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.
History

No history.

Subscriptions

Zyxel Usg100 Usg1000 Usg1000 Firmware Usg100 Firmware Usg110 Usg1100 Usg1100 Firmware Usg110 Firmware Usg1900 Usg1900 Firmware Usg20 Usg20-vpn Usg20-vpn Firmware Usg200 Usg2000 Usg2000 Firmware Usg200 Firmware Usg20 Firmware Usg20w Usg20w-vpn Usg20w-vpn Firmware Usg20w Firmware Usg210 Usg210 Firmware Usg2200-vpn Usg2200-vpn Firmware Usg300 Usg300 Firmware Usg310 Usg310 Firmware Usg40 Usg40 Firmware Usg40w Usg40w Firmware Usg50 Usg50 Firmware Usg60 Usg60 Firmware Usg60w Usg60w Firmware Usg Flex 100 Usg Flex 100 Firmware Usg Flex 100w Usg Flex 100w Firmware Usg Flex 200 Usg Flex 200 Firmware Usg Flex 500 Usg Flex 500 Firmware Usg Flex 700 Usg Flex 700 Firmware Zywall 110 Zywall 1100 Zywall 1100 Firmware Zywall 110 Firmware Zywall 310 Zywall 310 Firmware Zywall Atp100 Zywall Atp100 Firmware Zywall Atp100w Zywall Atp100w Firmware Zywall Atp200 Zywall Atp200 Firmware Zywall Atp500 Zywall Atp500 Firmware Zywall Atp700 Zywall Atp700 Firmware Zywall Atp800 Zywall Atp800 Firmware Zywall Vpn100 Zywall Vpn100 Firmware Zywall Vpn300 Zywall Vpn300 Firmware Zywall Vpn50 Zywall Vpn50 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: Zyxel

Published:

Updated: 2024-08-04T00:33:49.831Z

Reserved: 2021-06-17T00:00:00.000Z

Link: CVE-2021-35029

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-07-02T11:15:08.930

Modified: 2024-11-21T06:11:42.280

Link: CVE-2021-35029

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses