First published: Wed Sep 29 2021(Updated: )
A command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticated, local user to execute arbitrary OS commands.
Credit: security@zyxel.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel Zywall Vpn2s Firmware | =1.12\(abln.0\)c0 | |
Zyxel Zywall Vpn2s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-35028 is a command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12.
CVE-2021-35028 allows an authenticated, local user to execute arbitrary OS commands in the Zyxel VPN2S firmware version 1.12.
The severity of CVE-2021-35028 is rated as high with a score of 7.8.
To fix the CVE-2021-35028 vulnerability, update to a patched version of the Zyxel VPN2S firmware.
You can find more information about CVE-2021-35028 on the Zyxel website: https://www.zyxel.com/support/Zyxel_security_advisory_for_directory_traversal_and_command_injection_vulnerabilities_of_VPN2S_Firewall.shtml