Command Injection Vulnerability in Zyxel VPN2S Firmware
CVE-2021-35028

7.3HIGH

Key Information:

Vendor
Zyxel
Vendor
CVE Published:
29 September 2021

Summary

A command injection issue has been identified within the CGI program of the Zyxel VPN2S firmware version 1.12, enabling an authenticated local user to execute arbitrary operating system commands. This vulnerability poses a substantial risk to system integrity, allowing misuse of system resources and potential escalation of privileges.

Affected Version(s)

ZyWALL VPN2S Firmware 1.12(ABLN.0)C0

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.