CVE-2021-35033
A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password management could allow an attacker to obtain root access of the device, if the local attacker dismantles the device and uses a USB-to-UART cable to connect the device, or if the remote assistance feature had been enabled by an authenticated user.
Published:Nov 23, 2021
Last Modified:Nov 21, 2024
EPS:Nov 23, 2021
EPSS Score:0.00036
CVSS Score:7.8
Affected Products
Vendor
Product
Action
Vendor
Zyxel
Product
Nbg6818
Zyxel
Nbg6818
Vendor
Zyxel
Product
Nbg6818 Firmware
Zyxel
Nbg6818 Firmware
Vendor
Zyxel
Product
Nbg7815
Zyxel
Nbg7815
Vendor
Zyxel
Product
Nbg7815 Firmware
Zyxel
Nbg7815 Firmware
Vendor
Zyxel
Product
Wsq20
Zyxel
Wsq20
Vendor
Zyxel
Product
Wsq20 Firmware
Zyxel
Wsq20 Firmware
Vendor
Zyxel
Product
Wsq50
Zyxel
Wsq50
Vendor
Zyxel
Product
Wsq50 Firmware
Zyxel
Wsq50 Firmware
Vendor
Zyxel
Product
Wsq60
Zyxel
Wsq60
Vendor
Zyxel
Product
Wsq60 Firmware
Zyxel
Wsq60 Firmware
Vendor
Zyxel
Product
Wsr30
Zyxel
Wsr30
Vendor
Zyxel
Product
Wsr30 Firmware
Zyxel
Wsr30 Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
