High severity7.4NVD Advisory· Published Dec 29, 2021· Updated Jun 17, 2026
CVE-2021-35034
CVE-2021-35034
Description
An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device if the correct token can be intercepted.
Affected products
3cpe:2.3:o:zyxel:nbg6604_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:zyxel:nbg6604_firmware:*:*:*:*:*:*:*:*range: <1.00\(abir.9\)c0
- (no CPE)range: 1.00(ABIR.8)C0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.