CVE-2021-35028

HIGH

Zyxel ZyWALL VPN2S Firmware 1.12 - Authenticated OS Command Injection

Title source: llm
STIX 2.1

Description

A command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticated, local user to execute arbitrary OS commands.

Scores

CVSS v3 7.3
EPSS 0.0012
EPSS Percentile 31.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
zyxel/zywall_vpn2s_firmware 1.12\(abln.0\)c0
Published Sep 29, 2021
Tracked Since Feb 18, 2026