https://reddit.com/r/netsec/comments/1tkkq0m/zyxel_lowpriv_account_leaked_superadmin_ftps_and/: Zyxel low-priv account leaked super-admin, FTPS, and TR-069 secrets across router fleets
Published May 22, 2026
·Updated
Affected Software
5 affected components
Zyxel VMG3625-T50B
Zyxel CPE
Zyxel ONT
Zyxel LTE gateway
Zyxel 5G CPE
Frequently Asked Questions
1
What is the severity of CVE-2021-35036?
CVE-2021-35036 is classified as a high severity vulnerability due to its potential for unauthorized access and exposure of sensitive information.
2
How do I fix CVE-2021-35036?
To fix CVE-2021-35036, update your Zyxel firmware to the latest version provided by the manufacturer that addresses this vulnerability.
3
What devices are affected by CVE-2021-35036?
CVE-2021-35036 affects several Zyxel devices including the VMG3625-T50B, various Zyxel CPE, and the Zyxel LTE and 5G gateways.
4
What are the consequences of CVE-2021-35036?
The consequences of CVE-2021-35036 include the risk of super-admin credentials being leaked and unauthorized access to critical configurations.
5
Are there any known exploits for CVE-2021-35036?
Yes, there have been reports of exploits targeting CVE-2021-35036 that take advantage of the low-privileged access to retrieve sensitive information.