High severity7.8NVD Advisory· Published Nov 23, 2021· Updated Jun 17, 2026
CVE-2021-35033
CVE-2021-35033
Description
A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password management could allow an attacker to obtain root access of the device, if the local attacker dismantles the device and uses a USB-to-UART cable to connect the device, or if the remote assistance feature had been enabled by an authenticated user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
18- Zyxel/NBG6818 series firmwarev5Range: 1.00(ABSC.0)C0 through 1.00(ABSC.4)C0
- Zyxel/NBG7815 series firmwarev5Range: 1.00(ABSK.0)C0 through 1.00(ABSK.6)C0
- Zyxel/WSQ20 series firmwarev5Range: 1.00(ABOF.0)C0 through 1.00(ABOF.10)C0
- Zyxel/WSQ50 series firmwarev5Range: 1.00(ABKJ.0)C0 through 2.20(ABKJ.6)C0
- Zyxel/WSQ60 series firmwarev5Range: 1.00(ABND.0)C0 through 2.20(ABND.7)C0
- Zyxel/WSR30 series firmwarev5Range: 1.00(ABMY.0)C0 through 1.00(ABMY.11)C0
Patches
Vulnerability mechanics
References
2- www.tenable.com/security/research/tra-2022-06nvdExploitThird Party Advisory
- www.zyxel.com/support/Zyxel_security_advisory_for_pre-configured_password_management_vulnerability_of_home_routers_and_WiFi_systems.shtmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.