VYPR
High severity7.4NVD Advisory· Published Dec 29, 2021· Updated Jun 17, 2026

CVE-2021-35034

CVE-2021-35034

Description

An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device if the correct token can be intercepted.

Affected products

3
  • cpe:2.3:o:zyxel:nbg6604_firmware:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:zyxel:nbg6604_firmware:*:*:*:*:*:*:*:*range: <1.00\(abir.9\)c0
    • (no CPE)range: 1.00(ABIR.8)C0
  • Zyxel/NBG6604llm-fuzzy

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.