CVE-2021-35034: Critical severity zyxel nbg6604 vulnerability
Published Dec 29, 2021
·Updated
An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device if the correct token can be intercepted.
Affected Software
2 affected components
Zyxel NBG6604 firmware<1.00\(abir.9\)c0
Zyxel NBG6604
Event History
Dec 29, 2021
CVE Published
via MITRE·12:36 PM
Data Sourced
via MITRE·12:36 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-35034?
The severity of CVE-2021-35034 is critical with a score of 9.1.
2
What is CVE-2021-35034?
CVE-2021-35034 is an insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware.
3
How does CVE-2021-35034 impact the Zyxel NBG6604 firmware?
CVE-2021-35034 could allow a remote attacker to access the device if the correct token can be intercepted.
4
Is Zyxel NBG6604 firmware affected by CVE-2021-35034?
Yes, Zyxel NBG6604 firmware is affected by CVE-2021-35034.
5
How can I fix CVE-2021-35034?
To fix CVE-2021-35034, it is recommended to update the Zyxel NBG6604 firmware to the latest version available.