CVE-2021-35029

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
02/07/2021
Last modified:
08/07/2021

Description

An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:zyxel:usg1900_firmware:*:*:*:*:*:*:*:* 4.35 (including) 4.64 (including)
cpe:2.3:h:zyxel:usg1900:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg1100_firmware:*:*:*:*:*:*:*:* 4.35 (including) 4.64 (including)
cpe:2.3:h:zyxel:usg1100:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg310_firmware:*:*:*:*:*:*:*:* 4.35 (including) 4.64 (including)
cpe:2.3:h:zyxel:usg310:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg210_firmware:*:*:*:*:*:*:*:* 4.35 (including) 4.64 (including)
cpe:2.3:h:zyxel:usg210:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg110_firmware:*:*:*:*:*:*:*:* 4.35 (including) 4.64 (including)
cpe:2.3:h:zyxel:usg110:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg40_firmware:*:*:*:*:*:*:*:* 4.35 (including) 4.64 (including)
cpe:2.3:h:zyxel:usg40:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg40w_firmware:*:*:*:*:*:*:*:* 4.35 (including) 4.64 (including)
cpe:2.3:h:zyxel:usg40w:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg60_firmware:*:*:*:*:*:*:*:* 4.35 (including) 4.64 (including)