7.5
CVSSv2

CVE-2021-35029

Published: 02/07/2021 Updated: 08/07/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 up to and including 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 up to and including 5.01, which could allow a remote malicious user to execute arbitrary commands on an affected device.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zyxel usg1900_firmware

zyxel usg1100_firmware

zyxel usg310_firmware

zyxel usg210_firmware

zyxel usg110_firmware

zyxel usg40_firmware

zyxel usg40w_firmware

zyxel usg60_firmware

zyxel usg60w_firmware

zyxel usg300_firmware

zyxel usg1000_firmware

zyxel usg2000_firmware

zyxel usg20_firmware

zyxel usg20w_firmware

zyxel usg50_firmware

zyxel usg100_firmware

zyxel usg200_firmware

zyxel usg_flex_100_firmware

zyxel usg_flex_200_firmware

zyxel usg_flex_500_firmware

zyxel usg_flex_100w_firmware

zyxel usg_flex_700_firmware

zyxel zywall_atp100_firmware

zyxel zywall_atp100w_firmware

zyxel zywall_atp200_firmware

zyxel zywall_atp500_firmware

zyxel zywall_atp700_firmware

zyxel zywall_atp800_firmware

zyxel zywall_vpn50_firmware

zyxel zywall_vpn100_firmware

zyxel zywall_vpn300_firmware

zyxel usg20-vpn_firmware

zyxel usg20w-vpn_firmware

zyxel usg2200-vpn_firmware

zyxel zywall_110_firmware

zyxel zywall_310_firmware

zyxel zywall_1100_firmware