An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.

Project Subscriptions

Vendors Products
Usg1000 Subscribe
Usg1000 Firmware Subscribe
Usg100 Firmware Subscribe
Usg1100 Subscribe
Usg1100 Firmware Subscribe
Usg110 Firmware Subscribe
Usg1900 Subscribe
Usg1900 Firmware Subscribe
Usg20-vpn Subscribe
Usg20-vpn Firmware Subscribe
Usg2000 Subscribe
Usg2000 Firmware Subscribe
Usg200 Firmware Subscribe
Usg20 Firmware Subscribe
Usg20w-vpn Subscribe
Usg20w-vpn Firmware Subscribe
Usg20w Firmware Subscribe
Usg210 Firmware Subscribe
Usg2200-vpn Subscribe
Usg2200-vpn Firmware Subscribe
Usg300 Firmware Subscribe
Usg310 Firmware Subscribe
Usg40 Firmware Subscribe
Usg40w Firmware Subscribe
Usg50 Firmware Subscribe
Usg60 Firmware Subscribe
Usg60w Firmware Subscribe
Usg Flex 100 Subscribe
Usg Flex 100 Firmware Subscribe
Usg Flex 100w Subscribe
Usg Flex 100w Firmware Subscribe
Usg Flex 200 Subscribe
Usg Flex 200 Firmware Subscribe
Usg Flex 500 Subscribe
Usg Flex 500 Firmware Subscribe
Usg Flex 700 Subscribe
Usg Flex 700 Firmware Subscribe
Zywall 110 Subscribe
Zywall 1100 Subscribe
Zywall 1100 Firmware Subscribe
Zywall 110 Firmware Subscribe
Zywall 310 Subscribe
Zywall 310 Firmware Subscribe
Zywall Atp100 Subscribe
Zywall Atp100 Firmware Subscribe
Zywall Atp100w Subscribe
Zywall Atp100w Firmware Subscribe
Zywall Atp200 Subscribe
Zywall Atp200 Firmware Subscribe
Zywall Atp500 Subscribe
Zywall Atp500 Firmware Subscribe
Zywall Atp700 Subscribe
Zywall Atp700 Firmware Subscribe
Zywall Atp800 Subscribe
Zywall Atp800 Firmware Subscribe
Zywall Vpn100 Subscribe
Zywall Vpn100 Firmware Subscribe
Zywall Vpn300 Subscribe
Zywall Vpn300 Firmware Subscribe
Zywall Vpn50 Subscribe
Zywall Vpn50 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-21676 An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Zyxel

Published:

Updated: 2024-08-04T00:33:49.831Z

Reserved: 2021-06-17T00:00:00

Link: CVE-2021-35029

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-07-02T11:15:08.930

Modified: 2024-11-21T06:11:42.280

Link: CVE-2021-35029

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses