CVE-2021-35033 is a high-severity vulnerability affecting specific Zyxel NBG and WSQ series firmware versions, stemming from pre-configured password management. An attacker could gain root access to the device either by physically dismantling it and using a USB-to-UART cable, or remotely if the authenticated user has enabled the remote assistance feature. With a CVSS score of 7.8, the vulnerability has a low attack complexity and requires local or authenticated user access, but grants full confidentiality, integrity, and availability impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.00\(absc.5\)c0CPE matchmatch criteria | cpe:2.3:o:zyxel:nbg6818_firmware:*:*:*:*:*:*:*:* | ||
< 1.00\(absk.7\)c0CPE matchmatch criteria | cpe:2.3:o:zyxel:nbg7815_firmware:*:*:*:*:*:*:*:* | ||
< 1.00\(abof.11\)c0CPE matchmatch criteria | cpe:2.3:o:zyxel:wsq20_firmware:*:*:*:*:*:*:*:* | ||
< 2.20\(abkj.7\)c0CPE matchmatch criteria | cpe:2.3:o:zyxel:wsq50_firmware:*:*:*:*:*:*:*:* | ||
< 2.20\(abnd.8\)c0CPE matchmatch criteria | cpe:2.3:o:zyxel:wsq60_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Zyxel Routers and Home WiFi Systems - Unprotected Root Access via UART Using Default Password
Feb 28, 2022Zyxel Routers and Home WiFi Systems - Unprotected Root Access via UART Using Default Password
Feb 28, 2022Zyxel Routers and Home WiFi Systems - Unprotected Root Access via UART Using Default Password
Feb 28, 2022