Critical severity9.8NVD Advisory· Published Jul 2, 2021· Updated Jun 17, 2026
CVE-2021-35029
CVE-2021-35029
Description
An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.
Affected products
43- cpe:2.3:o:zyxel:usg_flex_100_firmware:*:*:*:*:*:*:*:*Range: >=4.35,<=5.01
- cpe:2.3:o:zyxel:usg_flex_100w_firmware:*:*:*:*:*:*:*:*Range: >=4.35,<=5.01
- cpe:2.3:o:zyxel:usg_flex_200_firmware:*:*:*:*:*:*:*:*Range: >=4.35,<=5.01
- cpe:2.3:o:zyxel:usg_flex_500_firmware:*:*:*:*:*:*:*:*Range: >=4.35,<=5.01
- cpe:2.3:o:zyxel:usg_flex_700_firmware:*:*:*:*:*:*:*:*Range: >=4.35,<=5.01
- cpe:2.3:o:zyxel:zywall_atp100_firmware:*:*:*:*:*:*:*:*Range: >=4.35,<=5.01
- cpe:2.3:o:zyxel:zywall_atp100w_firmware:*:*:*:*:*:*:*:*Range: >=4.35,<=5.01
- cpe:2.3:o:zyxel:zywall_atp200_firmware:*:*:*:*:*:*:*:*Range: >=4.35,<=5.01
- cpe:2.3:o:zyxel:zywall_atp500_firmware:*:*:*:*:*:*:*:*Range: >=4.35,<=5.01
- cpe:2.3:o:zyxel:zywall_atp700_firmware:*:*:*:*:*:*:*:*Range: >=4.35,<=5.01
- cpe:2.3:o:zyxel:zywall_atp800_firmware:*:*:*:*:*:*:*:*Range: >=4.35,<=5.01
- cpe:2.3:o:zyxel:zywall_vpn100_firmware:*:*:*:*:*:*:*:*Range: >=4.35,<=5.01
- cpe:2.3:o:zyxel:zywall_vpn300_firmware:*:*:*:*:*:*:*:*Range: >=4.35,<=5.01
- cpe:2.3:o:zyxel:zywall_vpn50_firmware:*:*:*:*:*:*:*:*Range: >=4.35,<=5.01
4.35 - 4.64+ 1 more
- (no CPE)range: 4.35 - 4.64
- (no CPE)range: 4.35 through 4.64
- Range: 4.35 - 5.01
- Range: 4.35 through 5.01
- Range: 4.35 through 5.01
- Range: 4.35 through 5.01
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.