First published: Wed Sep 29 2021(Updated: )
A directory traversal vulnerability in the web server of the Zyxel VPN2S firmware version 1.12 could allow a remote attacker to gain access to sensitive information.
Credit: security@zyxel.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel Zywall Vpn2s Firmware | =1.12\(abln.0\)c0 | |
Zyxel Zywall Vpn2s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-35027 is a directory traversal vulnerability in the web server of the Zyxel VPN2S firmware version 1.12.
A remote attacker can exploit CVE-2021-35027 by sending specially crafted requests to the affected web server, allowing them to gain unauthorized access to sensitive information.
The severity of CVE-2021-35027 is high, with a CVSS score of 7.5.
The Zyxel VPN2S firmware version 1.12 is affected by CVE-2021-35027.
To fix CVE-2021-35027, update the Zyxel VPN2S firmware to a version that has the necessary security patches.