https://reddit.com/r/cybersecurity/comments/1tlf7xf/zyxel_superadmin_credential_leak_expanded_from/: Zyxel super-admin credential leak expanded from one router image to CPE/ONT/LTE/5G devices + password gen algorithm.
Published May 23, 2026
·Updated
Affected Software
5 affected components
Zyxel VMG3625-T50B
Zyxel CPE devices
Zyxel ONT devices
Zyxel LTE devices
Zyxel 5G devices
Frequently Asked Questions
1
What is the severity of CVE-2021-35036?
CVE-2021-35036 has been classified with a low severity rating due to its access level requirements.
2
How do I fix CVE-2021-35036?
To mitigate CVE-2021-35036, update your Zyxel devices to the latest firmware that addresses this vulnerability.
3
What devices are affected by CVE-2021-35036?
CVE-2021-35036 affects various Zyxel devices including CPE, ONT, LTE, and 5G models.
4
What type of credential leak is involved in CVE-2021-35036?
CVE-2021-35036 involves a leak of super-admin credentials that could be exploited by low-privileged users.
5
What is the impact of CVE-2021-35036 on Zyxel devices?
The impact of CVE-2021-35036 allows potential unauthorized access to sensitive backend functionalities of affected Zyxel devices.