Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2021-35029

CVE-2021-35029: Zyxel USG Auth Bypass Vulnerability

CVE-2021-35029 is an authentication bypass flaw in Zyxel USG/Zywall firmware that enables remote attackers to execute arbitrary commands. This article covers the technical details, affected versions, and mitigation.

Updated:

CVE-2021-35029 Overview

CVE-2021-35029 is an authentication bypass vulnerability in the web-based management interface of Zyxel USG, ZyWALL, USG Flex, ATP, and VPN series firewalls. The flaw affects USG/ZyWALL firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01. A remote, unauthenticated attacker can leverage the bypass to execute arbitrary commands on an affected device. The weakness is categorized under CWE-287: Improper Authentication. Because the affected devices function as perimeter firewalls and VPN concentrators, successful exploitation grants attackers a foothold at the network edge.

Critical Impact

Unauthenticated remote attackers can bypass authentication on the web management interface and execute arbitrary commands on the underlying firewall, leading to full device compromise.

Affected Products

  • Zyxel USG and ZyWALL series running firmware versions 4.35 through 4.64 (including USG20, USG40, USG60, USG110, USG210, USG310, USG1100, USG1900, USG2000, ZyWALL 110/310/1100)
  • Zyxel USG Flex series (100, 100W, 200, 500, 700) running firmware versions 4.35 through 5.01
  • Zyxel ATP series (ATP100, ATP100W, ATP200, ATP500, ATP700, ATP800) and VPN series (VPN50, VPN100, VPN300, USG20-VPN, USG20W-VPN, USG2200-VPN) running firmware 4.35 through 5.01

Discovery Timeline

  • 2021-07-02 - CVE-2021-35029 published to NVD
  • 2024-11-21 - Last updated in NVD database

Technical Details for CVE-2021-35029

Vulnerability Analysis

The vulnerability resides in the web-based management interface exposed by Zyxel USG, ZyWALL, USG Flex, ATP, and VPN series appliances. The interface fails to correctly enforce authentication on certain request paths, allowing an attacker to interact with privileged functionality without valid credentials. After bypassing authentication, the attacker reaches command-handling logic that executes operating system commands on the device. This combination of authentication bypass and command execution converts a single network-reachable HTTP/HTTPS request into full administrative control of the firewall.

Root Cause

The root cause is improper authentication enforcement in the management web server. Specific management endpoints do not validate session state or credentials before processing requests, so requests crafted by an attacker are processed as if they came from an authenticated administrator. This is a classic [CWE-287] failure where security-relevant decisions are made without verifying the identity of the requester.

Attack Vector

Exploitation is network-based and requires no authentication or user interaction. An attacker reaches the management interface over HTTP or HTTPS, often on TCP/443 or TCP/8443, and submits crafted requests to the vulnerable endpoint. Because many of these appliances are deployed at the network perimeter, the management interface is frequently reachable from untrusted networks when WAN-side management is not properly restricted. Successful exploitation yields arbitrary command execution in the context of the firewall management process, enabling persistence, credential theft, lateral movement into protected networks, and tampering with firewall rules or VPN configurations.

No verified proof-of-concept code is published in the references for this CVE. For additional technical context, see the Zyxel Security Advisory.

Detection Methods for CVE-2021-35029

Indicators of Compromise

  • Unexpected HTTP/HTTPS requests to the Zyxel management interface from external IP addresses, especially to administrative endpoints.
  • New or modified administrative accounts, VPN users, or firewall rules that were not created by authorized administrators.
  • Outbound connections from the firewall management plane to unknown external hosts, indicating reverse shells or beacon traffic.
  • Unexpected configuration changes, restored backups, or firmware modifications appearing in device logs.

Detection Strategies

  • Inspect Zyxel device logs for authentication anomalies, failed-then-successful access patterns, and requests to management URIs without preceding login events.
  • Deploy IDS/IPS signatures that flag requests targeting known Zyxel management endpoints from WAN-side sources.
  • Correlate firewall configuration changes with administrator login timelines to surface unauthorized changes.

Monitoring Recommendations

  • Forward Zyxel syslog and configuration audit logs to a central SIEM and alert on administrative actions outside change windows.
  • Monitor for newly exposed management interfaces on the WAN side by running periodic external attack surface scans.
  • Track outbound connections originating from firewall management subnets, which should normally be minimal and well-defined.

How to Mitigate CVE-2021-35029

Immediate Actions Required

  • Upgrade USG/ZyWALL devices to firmware versions later than 4.64 and upgrade USG Flex, ATP, and VPN series devices to firmware versions later than 5.01 per the Zyxel advisory.
  • Restrict access to the web management interface so it is reachable only from trusted internal management networks or via VPN.
  • Disable WAN-side HTTP and HTTPS management until patches are applied and verified.
  • Rotate all administrative credentials, VPN pre-shared keys, and certificates on any device that may have been exposed.

Patch Information

Zyxel released fixed firmware addressing this authentication bypass. Refer to the Zyxel Security Advisory for attacks against security appliances for the specific firmware versions and download links for each affected model. Apply the vendor-supplied firmware to every affected USG, ZyWALL, USG Flex, ATP, and VPN appliance.

Workarounds

  • Apply access-control policies that limit the management interface to a small set of trusted source IP addresses.
  • Place the management interface behind a jump host or VPN and require multi-factor authentication for administrator access.
  • Where patching is delayed, temporarily disable remote management on WAN interfaces and use console or LAN-side access only.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.