CVE-2021-35029: Critical severity zyxel usg1900 firmware vulnerability
An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-35029?
CVE-2021-35029 is classified as a critical authentication bypass vulnerability.
How do I fix CVE-2021-35029?
To mitigate CVE-2021-35029, users should update their Zyxel devices to the latest firmware version that addresses the vulnerability.
Which Zyxel products are affected by CVE-2021-35029?
CVE-2021-35029 affects various Zyxel USG and Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01.
Can CVE-2021-35029 allow remote attacks?
Yes, CVE-2021-35029 allows remote attackers to execute arbitrary commands on affected devices.
Is there a known exploit for CVE-2021-35029?
Yes, CVE-2021-35029 has been reported to be actively exploited, making prompt remediation essential.