CVE-2021-35036
published 2022-03-01CVE-2021-35036: A cleartext storage of information vulnerability in the Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k could allow an authenticated attacker to obtain…
PriorityP431medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.48%
38.1th percentile
A cleartext storage of information vulnerability in the Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k could allow an authenticated attacker to obtain sensitive information from the configuration file.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | ax7501-b0_firmware | < 5.17\(abpc.2\)c0 | 5.17\(abpc.2\)c0 |
| zyxel | dx3301-t0_firmware | < 5.50\(abvy.3\)c0 | 5.50\(abvy.3\)c0 |
| zyxel | dx5401-b0_firmware | < 5.17\(abyo.2\)c0 | 5.17\(abyo.2\)c0 |
| zyxel | emg3525-t50b_firmware | < 5.50\(abpm.7\)c0 | 5.50\(abpm.7\)c0 |
| zyxel | emg5523-t50b_firmware | < 5.50\(abpm.7\)c0 | 5.50\(abpm.7\)c0 |
| zyxel | emg5723-t50k_firmware | < 5.50\(abom.8\)c0 | 5.50\(abom.8\)c0 |
| zyxel | ep240p_firmware | < 5.40\(abvh.0\)c0a03 | 5.40\(abvh.0\)c0a03 |
| zyxel | ex5401-b0_firmware | < 5.17\(abyo.2\)c0 | 5.17\(abyo.2\)c0 |
| zyxel | ex5501-b0_firmware | < 5.17\(abry.3\)c0 | 5.17\(abry.3\)c0 |
| zyxel | lte3301-plus_firmware | < 1.00\(abqu.6\)c0 | 1.00\(abqu.6\)c0 |
| zyxel | lte5388-m804_firmware | < 1.00\(abra.6\)c0 | 1.00\(abra.6\)c0 |
| zyxel | lte5388-s905_firmware | < 1.00\(abvi.6\)c0 | 1.00\(abvi.6\)c0 |
| zyxel | lte5398-m904_firmware | < 1.00\(abqv.2\)c0 | 1.00\(abqv.2\)c0 |
| zyxel | lte7240-m403_firmware | < 2.00\(abmg.6\)c0 | 2.00\(abmg.6\)c0 |
| zyxel | lte7461-m602_firmware | < 2.00\(abqn.6\)c0 | 2.00\(abqn.6\)c0 |
| zyxel | lte7480-m804_firmware | < 1.00\(abra.6\)c0 | 1.00\(abra.6\)c0 |
| zyxel | lte7480-s905_firmware | < 2.00\(abqt.6\)c0 | 2.00\(abqt.6\)c0 |
| zyxel | lte7485-s905_firmware | < 1.00\(abvn.6\)c0 | 1.00\(abvn.6\)c0 |
| zyxel | lte7490-m804_firmware | < v1.00\(abqy.5\)c0 | v1.00\(abqy.5\)c0 |
| zyxel | nr5101_firmware | < 1.00\(abvc.6\)c0 | 1.00\(abvc.6\)c0 |
| zyxel | nr7101_firmware | < 1.00\(abuv.7\)c0 | 1.00\(abuv.7\)c0 |
| zyxel | nr7102_firmware | < 1.00\(abyd.2\)c0 | 1.00\(abyd.2\)c0 |
| zyxel | pm7300-t0_firmware | < 5.42\(acbc.1\)c0 | 5.42\(acbc.1\)c0 |
| zyxel | pmg5317-t20b_firmware | < 5.40\(abki.4\)c0 | 5.40\(abki.4\)c0 |
| zyxel | pmg5617-t20b2_firmware | < 5.41\(acbb.1\)c0 | 5.41\(acbb.1\)c0 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-03-01
Published