Command Injection Vulnerability in Zyxel VPN2S Firmware
CVE-2021-35028
7.3HIGH
Summary
A command injection issue has been identified within the CGI program of the Zyxel VPN2S firmware version 1.12, enabling an authenticated local user to execute arbitrary operating system commands. This vulnerability poses a substantial risk to system integrity, allowing misuse of system resources and potential escalation of privileges.
Affected Version(s)
ZyWALL VPN2S Firmware 1.12(ABLN.0)C0
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved