Cleartext Information Storage Vulnerability in Zyxel VMG3625-T50B Firmware
CVE-2021-35036
6.5MEDIUM
Key Information:
- Vendor
Zyxel
- Status
- Vendor
- CVE Published:
- 1 March 2022
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2021-35036?
A vulnerability exists in the Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k, where sensitive information from the configuration file can be exposed. This flaw allows authenticated attackers to access data stored in cleartext, posing a risk for data confidentiality and integrity. Users of affected firmware should prioritize updating to secure their devices and prevent potential exploitation.
Affected Version(s)
VMG3625-T50B firmware V5.50(ABTL.0)b2k
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.