CVE-2021-35027: Path Traversal
Published Sep 29, 2021
·Updated
A directory traversal vulnerability in the web server of the Zyxel VPN2S firmware version 1.12 could allow a remote attacker to gain access to sensitive information.
Affected Software
2 affected components
Zyxel Zywall VPN 2S=1.12\(abln.0\)c0
Zyxel Zywall VPN 2S
Remediation
Event History
Sep 29, 2021
CVE Published
via MITRE·10:32 AM
Data Sourced
via MITRE·10:32 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-35027?
CVE-2021-35027 is a directory traversal vulnerability in the web server of the Zyxel VPN2S firmware version 1.12.
2
How can a remote attacker exploit CVE-2021-35027?
A remote attacker can exploit CVE-2021-35027 by sending specially crafted requests to the affected web server, allowing them to gain unauthorized access to sensitive information.
3
What is the severity of CVE-2021-35027?
The severity of CVE-2021-35027 is high, with a CVSS score of 7.5.
4
What software is affected by CVE-2021-35027?
The Zyxel VPN2S firmware version 1.12 is affected by CVE-2021-35027.
5
How can I fix CVE-2021-35027?
To fix CVE-2021-35027, update the Zyxel VPN2S firmware to a version that has the necessary security patches.