CVE-2021-4030

Cross-Site Request Forgery (CSRF) (CWE-352)

Published: Feb 24, 2022 / Updated: 33mo ago

010
CVSS 8.8EPSS 0.09%High
CVE info copied to clipboard

A cross-site request forgery vulnerability in the HTTP daemon of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary commands if they coerce or trick a local user to visit a compromised website with malicious scripts.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Timeline

First Article

Feedly found the first article mentioning CVE-2021-4030. See article

Feb 22, 2022 at 3:34 PM / github.com
EPSS

EPSS Score was set to: 0.09% (Percentile: 37.7%)

Sep 17, 2023 at 6:43 AM
Static CVE Timeline Graph

Affected Systems

Zyxel/nbg6816_firmware
+null more

Patches

www.zyxel.com
+null more

Attack Patterns

CAPEC-111: JSON Hijacking (aka JavaScript Hijacking)
+null more

References

Vulnerability Summary for the Week of February 21, 2022
Original release date: February 28, 2022 Last revised: March 1, 2022 High Vulnerabilities Primary Vendor -- Product Description Published CVSS Score Source & Patch Info airspan -- mimosa_management_platform MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization checks on multiple API functions. An attacker may gain access to these functions and achieve remote code execution, create a denial-of-service condition, and obtain sensitive information. 2022-02-18 10 CVE-2022-21141 MISC airspan -- mimosa_management_platform MMP: All versions prior to v1.0.3, PTP C-series:

News

Security Bulletin 9 Mar 2022 | #macos | #macsecurity
CVE Number Description Base Score Reference CVE-2020-15824 In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users... The post Security Bulletin 9 Mar 2022 #macos #macsecurity appeared first on NATIONAL CYBER SECURITY NEWS TODAY .
Zyxel Armor Z1 and Z2 routers cross-site request forgery | CVE-2021-4030
Zyxel Armor Z1 and Z2 routers are vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. Zyxel Armor Z1 and Z2 routers cross-site request forgery
Security Bulletin 2 Mar 2022 - Cyber Security Agency of Singapore
Security Bulletin 2 Mar 2022 Cyber Security Agency of Singapore
Security Bulletin 9 Mar 2022 - Cyber Security Agency of Singapore
Security Bulletin 9 Mar 2022 Cyber Security Agency of Singapore
Security Bulletin 2 Mar 2022 - Cyber Security Agency of Singapore
Security Bulletin 2 Mar 2022 Cyber Security Agency of Singapore
See 15 more articles and social media posts

CVSS V3.1

Attack Vector:Network
Attack Complexity:Low
Privileges Required:None
User Interaction:Required
Scope:Unchanged
Confidentiality:High
Integrity:High
Availability Impact:High

Categories

Be the first to know about critical vulnerabilities

Collect, analyze, and share vulnerability reports faster using AI