← Back to browse · API

CVE-2021-35029

Severity
CRITICAL
CVSS
9.8
EPSS
0.02255
Risk score
39.99
CISA KEV
No
PoC
No
Published
2021-07-02
Modified
2024-08-04
First seen
2026-08-07
Aliases
EUVD-2021-21676, GHSA-2H44-X2FR-537P
Products
Zyxel:ATP series firmware 4.35 through 5.01, Zyxel:USG FLEX series firmware 4.35 through 5.01, Zyxel:USG/Zywall series Firmware 4.35 through 4.64, Zyxel:VPN series Firmware 4.35 through 5.01
Sources
euvd EUVD-2021-21676

Description

An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.

References