ZeroHour

CVE-2021-35029

CVSS 3.1
9.8 critical
EPSS
2%p82
Published
()
Modified
Description

An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.

Vendors
zyxel
Products
usg1900 firmware, usg1100 firmware, usg310 firmware, usg210 firmware, usg110 firmware, usg40 firmware, usg40w firmware, usg60 firmware, usg60w firmware, usg300 firmware, usg1000 firmware, usg2000 firmware
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news