« Volver al listado

CVE-2021-35033

Estado: ModificadaAlta (7.8)—

A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password management could allow an attacker to obtain root access of the device, if the local attacker dismantles the device and uses a USB-to-UART cable to connect the device, or if the remote assistance feature had been enabled by an authenticated user.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (6)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-35033",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@zyxel.com.tw",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@zyxel.com.tw",
      "affectedData": [
        {
          "vendor": "Zyxel",
          "product": "NBG6818 series firmware",
          "versions": [
            {
              "status": "affected",
              "version": "1.00(ABSC.0)C0 through 1.00(ABSC.4)C0"
            }
          ]
        },
        {
          "vendor": "Zyxel",
          "product": "NBG7815 series firmware",
          "versions": [
            {
              "status": "affected",
              "version": "1.00(ABSK.0)C0 through 1.00(ABSK.6)C0"
            }
          ]
        },
        {
          "vendor": "Zyxel",
          "product": "WSQ20 series firmware",
          "versions": [
            {
              "status": "affected",
              "version": "1.00(ABOF.0)C0 through 1.00(ABOF.10)C0"
            }
          ]
        },
        {
          "vendor": "Zyxel",
          "product": "WSQ50 series firmware",
          "versions": [
            {
              "status": "affected",
              "version": "1.00(ABKJ.0)C0 through 2.20(ABKJ.6)C0"
            }
          ]
        },
        {
          "vendor": "Zyxel",
          "product": "WSQ60 series firmware",
          "versions": [
            {
              "status": "affected",
              "version": "1.00(ABND.0)C0 through 2.20(ABND.7)C0"
            }
          ]
        },
        {
          "vendor": "Zyxel",
          "product": "WSR30 series firmware",
          "versions": [
            {
              "status": "affected",
              "version": "1.00(ABMY.0)C0 through 1.00(ABMY.11)C0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-11-23T22:15:07.623",
  "references": [
    {
      "url": "https://www.tenable.com/security/research/tra-2022-06",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "security@zyxel.com.tw"
    },
    {
      "url": "https://www.zyxel.com/support/Zyxel_security_advisory_for_pre-configured_password_management_vulnerability_of_home_routers_and_WiFi_systems.shtml",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@zyxel.com.tw"
    },
    {
      "url": "https://www.tenable.com/security/research/tra-2022-06",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.zyxel.com/support/Zyxel_security_advisory_for_pre-configured_password_management_vulnerability_of_home_routers_and_WiFi_systems.shtml",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@zyxel.com.tw",
      "description": [
        {
          "lang": "en",
          "value": "CWE-260"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password management could allow an attacker to obtain root access of the device, if the local attacker dismantles the device and uses a USB-to-UART cable to connect the device, or if the remote assistance feature had been enabled by an authenticated user."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad en versiones específicas del firmware de Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60 y WSR30 con administación de contraseñas preconfigurada podría permitir a un atacante obtener acceso root del dispositivo, si el atacante local desmonta el dispositivo y usa un cable USB a UART para conectarlo, o si la funcionalidad remote assistance ha sido habilitada por un usuario autenticado"
    }
  ],
  "lastModified": "2026-06-17T03:57:00.923",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:zyxel:nbg6818_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A2D09B3-6B56-483A-AB24-808930548DA4",
              "versionEndExcluding": "1.00\\(absc.5\\)c0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:zyxel:nbg6818:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "48E677C4-EE44-49C4-8CD5-CABE12F00097"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:zyxel:nbg7815_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E77E348E-B055-4D4F-A7E2-3209504DF004",
              "versionEndExcluding": "1.00\\(absk.7\\)c0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:zyxel:nbg7815:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D2E6D3DD-B789-4984-BE39-717071EC5B4E"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:zyxel:wsq20_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7FC79265-D940-4D82-A220-A28D435DDEF1",
              "versionEndExcluding": "1.00\\(abof.11\\)c0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:zyxel:wsq20:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "49AD416D-70DC-49E9-AEBB-3DB68E1E42D7"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:zyxel:wsq50_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FB22F798-9303-45FB-AD7D-10062177D564",
              "versionEndExcluding": "2.20\\(abkj.7\\)c0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:zyxel:wsq50:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B604D99D-276D-48B3-A696-18A496F3DCFF"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:zyxel:wsq60_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E67B738F-87A9-461C-93E1-45A600B73F62",
              "versionEndExcluding": "2.20\\(abnd.8\\)c0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:zyxel:wsq60:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "36E6D0E9-9BA8-42C4-9D6D-6DED3CA3BFEB"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:zyxel:wsr30_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "41B324F6-3588-468E-A63B-F621ABEDA92B",
              "versionEndExcluding": "1.00\\(abmy.12\\)c0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:zyxel:wsr30:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2F062047-27C3-4FCE-A1BB-A3ED6E3BDA05"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security@zyxel.com.tw"
}