Vulnerability Details CVE-2021-4030
A cross-site request forgery vulnerability in the HTTP daemon of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary commands if they coerce or trick a local user to visit a compromised website with malicious scripts.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 35.2%
CVSS Severity
CVSS v3 Score 8.0
CVSS v2 Score 6.8
Products affected by CVE-2021-4030
-
cpe:2.3:h:zyxel:nbg6816:-
-
cpe:2.3:h:zyxel:nbg6817:-
-
cpe:2.3:o:zyxel:nbg6816_firmware:1.00(aawb.10)c0
-
cpe:2.3:o:zyxel:nbg6817_firmware:*