CVE-2021-35031: OS Command Injection
A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authenticated LAN user to execute arbitrary OS commands via the GUI of the vulnerable device.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this Zyxel firmware vulnerability?
The vulnerability ID for this Zyxel firmware vulnerability is CVE-2021-35031.
How does this vulnerability in Zyxel firmware impact users?
This vulnerability in Zyxel firmware could allow an authenticated LAN user to execute arbitrary OS commands via the GUI of the vulnerable device.
Which Zyxel firmware versions are affected by this vulnerability?
Zyxel GS1900 series firmware versions 2.70(aahh.0)-20211208, XGS1210 series firmware version 1.00(abty.5)c0, and XGS1250 series firmware version 1.00(abwe.1)c0 are affected by this vulnerability.
What is the severity level of this vulnerability?
This vulnerability has a severity level of high (8).
How can I fix this vulnerability in Zyxel firmware?
To fix this vulnerability, it is recommended to update the firmware to a version that is not affected by the vulnerability.