Record summary

CVE-2021-3297 has a selected CVSS score of 7.8 (high); EIP currently links 1 Nuclei template.

Description

On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Aug 19, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHZyxel NBG2105 V1.00(AAGU.2)C0 - Authentication BypassCVSS 7.8

Zyxel NBG2105 V1.00(AAGU.2)C0 devices are susceptible to authentication bypass vulnerabilities because setting the login cookie to 1 provides administrator access.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information, unauthorized configuration changes, and potential compromise of the affected device.

Remediation

Apply the latest firmware update provided by Zyxel to fix the authentication bypass vulnerability.

WeaknessesCWE-287
Authorsgy741
Template tagscvecve2021zyxelauth-bypassroutervkevvuln
CVSS vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:zyxel:nbg2105_firmware:v1.00\(aagu.2\)c0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

5