CVE-2021-4030

HIGH

Zyxel ARMOR Z1/Z2 Firmware - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

A cross-site request forgery vulnerability in the HTTP daemon of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary commands if they coerce or trick a local user to visit a compromised website with malicious scripts.

References (1)

Core 1

Scores

CVSS v3 8.0
EPSS 0.0014
EPSS Percentile 34.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (2)
zyxel/nbg6816_firmware 1.00\(aawb.10\)c0
zyxel/nbg6817_firmware < 1.00\(abcs.11\)c0
Published Feb 24, 2022
Tracked Since Feb 18, 2026