CVE-2021-35029

CRITICALCVSS 9.8/10EPSS 2.25%

Last modified

CVE-2021-35029 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.. EPSS estimates a 2.25% chance of exploitation in the next 30 days.

Description

An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
2.25%

80.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
ZyxelUsg1900 Firmware>= 4.35, <= 4.64
ZyxelUsg1100 Firmware>= 4.35, <= 4.64
ZyxelUsg310 Firmware>= 4.35, <= 4.64
ZyxelUsg210 Firmware>= 4.35, <= 4.64
ZyxelUsg110 Firmware>= 4.35, <= 4.64
ZyxelUsg40 Firmware>= 4.35, <= 4.64
ZyxelUsg40w Firmware>= 4.35, <= 4.64
ZyxelUsg60 Firmware>= 4.35, <= 4.64
ZyxelUsg60w Firmware>= 4.35, <= 4.64
ZyxelUsg300 Firmware>= 4.35, <= 4.64
ZyxelUsg1000 Firmware>= 4.35, <= 4.64
ZyxelUsg2000 Firmware>= 4.35, <= 4.64
ZyxelUsg20 Firmware>= 4.35, <= 4.64
ZyxelUsg20w Firmware>= 4.35, <= 4.64
ZyxelUsg50 Firmware>= 4.35, <= 4.64
ZyxelUsg100 Firmware>= 4.35, <= 4.64
ZyxelUsg200 Firmware>= 4.35, <= 4.64
ZyxelUsg Flex 100 Firmware>= 4.35, <= 5.01
ZyxelUsg Flex 200 Firmware>= 4.35, <= 5.01
ZyxelUsg Flex 500 Firmware>= 4.35, <= 5.01
ZyxelUsg Flex 100w Firmware>= 4.35, <= 5.01
ZyxelUsg Flex 700 Firmware>= 4.35, <= 5.01
ZyxelZywall Atp100 Firmware>= 4.35, <= 5.01
ZyxelZywall Atp100w Firmware>= 4.35, <= 5.01
ZyxelZywall Atp200 Firmware>= 4.35, <= 5.01
ZyxelZywall Atp500 Firmware>= 4.35, <= 5.01
ZyxelZywall Atp700 Firmware>= 4.35, <= 5.01
ZyxelZywall Atp800 Firmware>= 4.35, <= 5.01
ZyxelZywall Vpn50 Firmware>= 4.35, <= 5.01
ZyxelZywall Vpn100 Firmware>= 4.35, <= 5.01
ZyxelZywall Vpn300 Firmware>= 4.35, <= 5.01
ZyxelUsg20-Vpn Firmware>= 4.35, <= 5.01
ZyxelUsg20w-Vpn Firmware>= 4.35, <= 5.01
ZyxelUsg2200-Vpn Firmware>= 4.35, <= 5.01
ZyxelZywall 110 Firmware>= 4.35, <= 5.01
ZyxelZywall 310 Firmware>= 4.35, <= 5.01
ZyxelZywall 1100 Firmware>= 4.35, <= 5.01

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-35029?
An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.
How severe is CVE-2021-35029?
CVE-2021-35029 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 2.25% probability of exploitation in the next 30 days.
How do I fix CVE-2021-35029?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-35029?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST