A cross-site request forgery vulnerability exists within the ZyXEL Armor Z1 AC2350 and Z2 AC2600 series. Exploitation of the vulnerability allows for attackers to run arbitrary commands on vulnerable versions of the firmware under the context of the root user. Exploitation requires either that the attacker has access to the local network or is able to coerce a local user into visiting a malicious website.
- Exodus Intelligence: EIP-521a3b40
- MITRE CVE: CVE-2021-4030
- CVSSv2 Score: 7.9
- Exodus Intelligence
- Disclosed to affected vendor: December 14th, 2021
- Disclosed to public: February 22nd, 2022
Readers of this advisory who are interested in receiving further details around the vulnerability, mitigations, detection guidance, and more can contact us at firstname.lastname@example.org.
Researchers who are interested in monetizing their 0Day and NDay can work with us through our Research Sponsorship Program.