PT-2021-5182 · Zyxel · Zyxel Vpn2S

Published

2021-09-29

·

Updated

2021-11-09

·

CVE-2021-35027

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zyxel VPN2S firmware version 1.12
Description A directory traversal vulnerability in the web server of the Zyxel VPN2S firmware could allow a remote attacker to gain access to sensitive information. This issue exists due to incorrect restriction of the directory path name with limited access. The exploitation of this vulnerability may allow a remote attacker to obtain confidential information.
Recommendations For Zyxel VPN2S firmware version 1.12, consider restricting access to the web server until a patch is available. As a temporary workaround, limit the exposure of sensitive information by implementing additional security measures, such as configuring the firewall to restrict incoming connections to the web server. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05982
CVE-2021-35027

Affected Products

Zyxel Vpn2S