VYPR
High severity7.4NVD Advisory· Published Dec 29, 2021· Updated Jun 17, 2026

CVE-2021-35034

CVE-2021-35034

Description

An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device if the correct token can be intercepted.

Affected products

3
  • Zyxel/NBG6604 series firmwarev5
    Range: 1.00(ABIR.8)C0
  • Zyxel/NBG6604llm-fuzzy
  • cpe:2.3:o:zyxel:nbg6604_firmware:*:*:*:*:*:*:*:*
    Range: <1.00\(abir.9\)c0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.