CVE-2021-35029

An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ZyxelCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
VendorProductVersion
zyxelusg1900_firmware
4.35 ≤
𝑥
≤ 4.64
zyxelusg1100_firmware
4.35 ≤
𝑥
≤ 4.64
zyxelusg310_firmware
4.35 ≤
𝑥
≤ 4.64
zyxelusg210_firmware
4.35 ≤
𝑥
≤ 4.64
zyxelusg110_firmware
4.35 ≤
𝑥
≤ 4.64
zyxelusg40_firmware
4.35 ≤
𝑥
≤ 4.64
zyxelusg40w_firmware
4.35 ≤
𝑥
≤ 4.64
zyxelusg60_firmware
4.35 ≤
𝑥
≤ 4.64
zyxelusg60w_firmware
4.35 ≤
𝑥
≤ 4.64
zyxelusg300_firmware
4.35 ≤
𝑥
≤ 4.64
zyxelusg1000_firmware
4.35 ≤
𝑥
≤ 4.64
zyxelusg2000_firmware
4.35 ≤
𝑥
≤ 4.64
zyxelusg20_firmware
4.35 ≤
𝑥
≤ 4.64
zyxelusg20w_firmware
4.35 ≤
𝑥
≤ 4.64
zyxelusg50_firmware
4.35 ≤
𝑥
≤ 4.64
zyxelusg100_firmware
4.35 ≤
𝑥
≤ 4.64
zyxelusg200_firmware
4.35 ≤
𝑥
≤ 4.64
zyxelusg_flex_100_firmware
4.35 ≤
𝑥
≤ 5.01
zyxelusg_flex_200_firmware
4.35 ≤
𝑥
≤ 5.01
zyxelusg_flex_500_firmware
4.35 ≤
𝑥
≤ 5.01
zyxelusg_flex_100w_firmware
4.35 ≤
𝑥
≤ 5.01
zyxelusg_flex_700_firmware
4.35 ≤
𝑥
≤ 5.01
zyxelzywall_atp100_firmware
4.35 ≤
𝑥
≤ 5.01
zyxelzywall_atp100w_firmware
4.35 ≤
𝑥
≤ 5.01
zyxelzywall_atp200_firmware
4.35 ≤
𝑥
≤ 5.01
zyxelzywall_atp500_firmware
4.35 ≤
𝑥
≤ 5.01
zyxelzywall_atp700_firmware
4.35 ≤
𝑥
≤ 5.01
zyxelzywall_atp800_firmware
4.35 ≤
𝑥
≤ 5.01
zyxelzywall_vpn50_firmware
4.35 ≤
𝑥
≤ 5.01
zyxelzywall_vpn100_firmware
4.35 ≤
𝑥
≤ 5.01
zyxelzywall_vpn300_firmware
4.35 ≤
𝑥
≤ 5.01
zyxelusg20-vpn_firmware
4.35 ≤
𝑥
≤ 5.01
zyxelusg20w-vpn_firmware
4.35 ≤
𝑥
≤ 5.01
zyxelusg2200-vpn_firmware
4.35 ≤
𝑥
≤ 5.01
zyxelzywall_110_firmware
4.35 ≤
𝑥
≤ 5.01
zyxelzywall_310_firmware
4.35 ≤
𝑥
≤ 5.01
zyxelzywall_1100_firmware
4.35 ≤
𝑥
≤ 5.01
𝑥
= Vulnerable software versions