CVE-2021-4029

HIGH

Zyxel ARMOR Z1/Z2 - Command Injection

Title source: llm
STIX 2.1

Description

A command injection vulnerability in the CGI program of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary OS commands via a LAN interface.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0060
EPSS Percentile 69.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (2)
zyxel/nbg6816_firmware 1.00\(aawb.10\)c0
zyxel/nbg6817_firmware < 1.00\(abcs.11\)c0
Published Feb 24, 2022
Tracked Since Feb 18, 2026