PT-2021-5182 · Zyxel · Zyxel Vpn2S
Published
2021-09-29
·
Updated
2021-11-09
·
CVE-2021-35027
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Zyxel VPN2S firmware version 1.12
Description
A directory traversal vulnerability in the web server of the Zyxel VPN2S firmware could allow a remote attacker to gain access to sensitive information. This issue exists due to incorrect restriction of the directory path name with limited access. The exploitation of this vulnerability may allow a remote attacker to obtain confidential information.
Recommendations
For Zyxel VPN2S firmware version 1.12, consider restricting access to the web server until a patch is available. As a temporary workaround, limit the exposure of sensitive information by implementing additional security measures, such as configuring the firewall to restrict incoming connections to the web server. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zyxel Vpn2S