CVE-2021-35036 affects Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k. Although the CVE summary describes the issue as cleartext storage of information in a configuration file, the provided technical context indicates the practical vulnerability is an authenticated information exposure path: a low-privileged authenticated session could query DAL handlers, including login_privilege and tr69, and receive backend objects containing sensitive credentials and secrets in the response. Exposed data reportedly included higher-privilege local account information, FTPS credentials, and TR-069 management secrets. In effect, insufficient access control on backend configuration/management data allowed authenticated users with limited privileges to retrieve sensitive information that should not have been disclosed to them.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is primarily a research publication and lab bundle centered on CVE-2021-35036 affecting Zyxel devices. Most top-level files are static website content (README, index.html, CSS, icons) that document how authenticated low-privilege users could retrieve higher-privilege credentials from Zyxel DAL-backed management functionality. The actual actionable code is confined to the zyxel-vmg8825-b50b-keygen-lab directory. The lab bundle contains two shell wrappers, genpass and isoldserial, plus QEMU launchers for Windows and Linux. The genpass script validates a supplied modem serial number, exports it as SERIAL, sets LD_LIBRARY_PATH and LD_PRELOAD, and invokes the vendor binary /opt/genpass/getpassword. Based on the repository documentation and help text, this produces supervisor, admin, and Wi-Fi password families derived from the serial number. The isoldserial script performs similar validation and invokes /opt/genpass/checkserial to determine old/new password algorithm behavior. These are not remote exploitation scripts; they are local tooling for credential derivation within an emulated Zyxel runtime. The QEMU launch scripts boot an ARM Zyxel filesystem image and expose guest SSH on host TCP port 2222 via hostfwd=tcp::2222-:22. The help text documents logging into the emulated router as root/root and then running genpass manually. This makes the repository operational as a local credential-recovery lab rather than a turnkey network exploit. Overall purpose: document the vulnerability, show its architectural significance across Zyxel product lines, and provide a reproducible VMG8825-B50B emulation environment demonstrating vendor password-generation logic. Main exploit capability: deriving privileged local/admin/supervisor/Wi-Fi credentials from device identity inputs, which supports the broader claim that exposed credential-handling components made CVE-2021-35036 especially impactful.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.