High severity7.3NVD Advisory· Published Sep 29, 2021· Updated Jun 17, 2026
CVE-2021-35028
CVE-2021-35028
Description
A command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticated, local user to execute arbitrary OS commands.
Affected products
3- cpe:2.3:o:zyxel:zywall_vpn2s_firmware:1.12\(abln.0\)c0:*:*:*:*:*:*:*
- Range: 1.12(ABLN.0)C0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.