CVE-2021-35028: OS Command Injection
A command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticated, local user to execute arbitrary OS commands.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-35028?
CVE-2021-35028 is a command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12.
How does CVE-2021-35028 affect Zyxel Zywall Vpn2s Firmware?
CVE-2021-35028 allows an authenticated, local user to execute arbitrary OS commands in the Zyxel VPN2S firmware version 1.12.
What is the severity of CVE-2021-35028?
The severity of CVE-2021-35028 is rated as high with a score of 7.8.
How can I fix CVE-2021-35028 vulnerability?
To fix the CVE-2021-35028 vulnerability, update to a patched version of the Zyxel VPN2S firmware.
Where can I find more information about CVE-2021-35028?
You can find more information about CVE-2021-35028 on the Zyxel website: https://www.zyxel.com/support/Zyxel_security_advisory_for_directory_traversal_and_command_injection_vulnerabilities_of_VPN2S_Firewall.shtml