A buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmware versions through V5.50(ABOM.8.4)C0 could allow an attacker to cause a temporary denial of service (DoS) condition against the web management interface by sending a crafted HTTP POST request to a vulnerable device
Published Dec 3, 2024
7.5
HIGHCVSS 3.1
EPSS 0.52%
Description
A buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmware versions through V5.50(ABOM.8.4)C0 could allow an attacker to cause a temporary denial of service (DoS) condition against the web management interface by sending a crafted HTTP POST request to a vulnerable device.
Affected products
-
- Version <= V5.50(ABOM.8.4)C0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Zyxel | VMG8825-T50K firmware | unaffected |
|
Configuration 1
- < 1.00\(abqu.6\)c0
Running on/with
- n/a
Configuration 2
- < 1.00\(absq.5\)c0
Running on/with
- n/a
Configuration 3
- < 1.00\(abq.5\)c0
Running on/with
- n/a
Configuration 4
- < 1.00\(abra.10\)c0
Running on/with
- n/a
Configuration 5
- < 1.00\(abqy.9\)c0
Running on/with
- n/a
Configuration 6
- < 1.00\(abu.11\)c0
Configuration 7
- < 1.00\(abyd.4\)c0
Configuration 8
- < 1.16\(accg.1\)c0
Running on/with
- n/a
Configuration 9
- < 1.16\(accc.1\)c0
Running on/with
- n/a
Configuration 10
- < 1.18\(acca.5\)c0
Running on/with
- n/a
Configuration 11
- < 5.50\(aby.5.4\)c0
Configuration 12
- < 5.50\(aby.5.4\)c0
Configuration 13
- < 5.50\(aby.5.4\)c0
Configuration 14
- < 5.17\(abyl.8\)c0
Configuration 15
- < 5.17\(abyl.8\)c0
Configuration 16
- < 5.17\(abyo.6.4\)c0
Configuration 17
- < 5.17\(abyo.6.4\)c0
Configuration 18
- < 5.19\(acjq.1\)c0
Configuration 19
- < 5.50\(acdi.2\)c0
Configuration 20
- < 5.50\(aby.5.4\)c0
Configuration 21
- < 5.50\(aby.5.4\)c0
Configuration 22
- < 5.50\(aby.5.4\)c0
Configuration 23
- < 5.44\(achr.3\)c0
Configuration 24
- < 5.44\(achr.3\)c0
Configuration 25
- < 5.17\(abup.13\)c0
Configuration 26
- < 5.17\(abup.13\)c0
Configuration 27
- < 5.70\(acif.0.4\)c0
Configuration 28
- < 5.17\(abyo.6.4\)c0
Configuration 29
- < 5.17\(abyo.6.4\)c0
Configuration 30
- < 5.17\(abry.5.3\)c0
Configuration 31
- < 5.17\(abqx.11\)c0
Configuration 32
- < 5.70\(aceg4.2\)c0
Configuration 33
- < 5.70\(acdz.3.4\)c0
Configuration 34
- < 5.70\(acdz.3.4\)c0
Configuration 35
- < 5.70\(acdz.3.4\)c0
Configuration 36
- < 5.18\(achn.1.3\)c0
Configuration 37
- < 5.18\(acak.1.1\)c0
Configuration 38
- < 5.50\(abpm.9.3\)c0
Running on/with
- n/a
Configuration 39
- < 5.50\(abpm.9.3\)c0
Running on/with
- n/a
Configuration 40
- < 5.50\(abom.8.5\)c0
Running on/with
- n/a
Configuration 41
- < 5.13\(abnp.8\)c1
Running on/with
- n/a
Configuration 42
- < 5.50\(abpm.9.3\)c0
Running on/with
- n/a
Configuration 43
- < 5.13\(ably.9\)c1
Running on/with
- n/a
Configuration 44
- < 5.50\(abom.8.5\)c0
Running on/with
- n/a
Configuration 45
- < 5.15\(abqa.2.3\)c0
Running on/with
- n/a
Configuration 46
- < 5.15\(abqa.2.3\)c0
Running on/with
- n/a
Configuration 47
- < 5.13\(abrl.5.2\)c0
Running on/with
- n/a
Configuration 48
- < 5.13\(ably.9\)c1
Running on/with
- n/a
Configuration 49
- < 5.50\(abpm.9.3\)c0
Running on/with
- n/a
Configuration 50
- < 5.50\(abom.8.5\)c0
Running on/with
- n/a
Configuration 51
- < 5.50\(abpy.1\)b26
Running on/with
- n/a
Configuration 52
- < 5.17\(abpc.5.3\)c0
Configuration 53
- < 5.17\(abpc.5.3\)c0
Configuration 54
- < 5.42\(acbf.3\)c0
Configuration 55
- < 5.42\(acbf.3\)c0
Configuration 56
- < 5.42\(abyy.2.3\)c0
Configuration 57
- < 5.61\(ackk.0.1\)c0
Configuration 58
- < 5.44\(acjb.1.1\)c0
Configuration 59
- < 5.44\(achk.0.3\)c0
Configuration 60
- < 5.44\(ackb.0.1\)c0
Configuration 61
- < 5.50\(abl.4.4\)c0
Configuration 62
- < 5.17\(abe.2.6\)c0
Configuration 63
- < 5.17\(abe.2.6\)c0
Configuration 64
- < 5.70\(aceb.3.3\)c0
Configuration 65
- < 5.18\(acgj0.1\)c0
-
- Version 0StatusaffectedConstraints<=5.17\(abpc.5.2\)c0
- Version
-
- Version 0StatusaffectedConstraints<=5.17\(abpc.5.2\)c0
- Version
-
- Version 0StatusaffectedConstraints<=5.50\(abvy.5.3\)c0
- Version
-
- Version 0StatusaffectedConstraints<=5.50(abvy.5.3)c0
- Version
-
- Version 0StatusaffectedConstraints<=5.50\(abvy.5.3\)c0
- Version
-
- Version 0StatusaffectedConstraints<=5.17\(abyl.7\)c0
- Version
-
- Version 0StatusaffectedConstraints<=5.17\(abyl.7\)c0
- Version
-
- Version 0StatusaffectedConstraints<=5.17\(abyo.6.3\)c0
- Version
-
- Version 0StatusaffectedConstraints<=5.17\(abyo.6.3\)c0
- Version
-
- Version 0StatusaffectedConstraints<=5.19\(acjq.0\)c0
- Version
-
- Version 0StatusaffectedConstraints<=5.50\(acdi.1\)c0
- Version
-
- Version 0StatusaffectedConstraints<=1.00\(abqu.5\)c0
- Version
-
- Version 0StatusaffectedConstraints<=1.00\(absq.4\)c0
- Version
-
- Version 0StatusaffectedConstraints<=1.00\(abqv.4\)c0
- Version
-
- Version 0StatusaffectedConstraints<=1.00\(abra.9\)c0
- Version
-
- Version 0StatusaffectedConstraints<=1.00\(abqy.8\)c0
- Version
-
- Version 0StatusaffectedConstraints<=1.18\(acca.4\)c0
- Version
-
- Version 0StatusaffectedConstraints<1.16\(accg.0\)c0
- Version
-
- Version 0StatusaffectedConstraints<=1.16\(accc.0\)c0
- Version
-
- Version 0StatusaffectedConstraints<=1.00\(abuv.10\)c0
- Version
-
- Version 0StatusaffectedConstraints<=v1.00\(abyd.3\)c0
- Version
-
- Version 0StatusaffectedConstraints<=5.42(acbf.2.1)c0
- Version
-
- Version 0StatusaffectedConstraints<=5.42\(acbf.2.1\)c0
- Version
-
- Version 0StatusaffectedConstraints<=5.42\(abyy.2.2\)c0
- Version
-
- Version 0StatusaffectedConstraints<=5.61\(ackk.0\)c0
- Version
-
- Version 0StatusaffectedConstraints<=5.44\(achk.0.2\)c0
- Version 0StatusaffectedConstraints<=5.44\(acjb.1\)c0
- Version
-
- Version 0StatusaffectedConstraints<=5.44\(ackb.0\)c0
- Version
-
- Version 0StatusaffectedConstraints<=5.50\(abom.8.4\)c0
- Version
-
- Version 0StatusaffectedConstraints<=5.50\(abvl.4.3\)c0
- Version
-
- Version 0StatusaffectedConstraints<=5.17\(abve.2.5\)c0
- Version
-
- Version 0StatusaffectedConstraints<=5.17(abve.2.5)c0
- Version
-
- Version 0StatusaffectedConstraints<=5.70\(aceb.3.2\)c0
- Version
-
- Version 0StatusaffectedConstraints<=5.18\(acgj.0\)c2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Zyxel | Ax7501-B0 Firmware | n/a |
| |||||||||
| Zyxel | Ax7501-B1 Firmware | n/a |
| |||||||||
| Zyxel | Dx3300-T0 Firmware | n/a |
| |||||||||
| Zyxel | Dx3300-T1 Firmware | n/a |
| |||||||||
| Zyxel | Dx3301-T0 Firmware | n/a |
| |||||||||
| Zyxel | Dx4510-B0 Firmware | n/a |
| |||||||||
| Zyxel | Dx4510-B1 Firmware | n/a |
| |||||||||
| Zyxel | Dx5401-B0 Firmware | n/a |
| |||||||||
| Zyxel | Dx5401 B1 Firmware | n/a |
| |||||||||
| Zyxel | Ee6510-10 Firmware | n/a |
| |||||||||
| Zyxel | Ex2210-T0 Firmware | n/a |
| |||||||||
| Zyxel | Lte3301-Plus Firmware | n/a |
| |||||||||
| Zyxel | Lte5388-M804 Firmware | n/a |
| |||||||||
| Zyxel | Lte5398-M904 Firmware | n/a |
| |||||||||
| Zyxel | Lte7480-M804 Firmware | n/a |
| |||||||||
| Zyxel | Lte7490-M904 Firmware | n/a |
| |||||||||
| Zyxel | Nebula Lte3301-Plus Firmware | n/a |
| |||||||||
| Zyxel | Nebula Nr5101 Firmware | n/a |
| |||||||||
| Zyxel | Nebula Nr7101 Firmware | n/a |
| |||||||||
| Zyxel | Nr7101 Firmware | n/a |
| |||||||||
| Zyxel | Nr7102 Firmware | n/a |
| |||||||||
| Zyxel | Pm3100-T0 Firmware | n/a |
| |||||||||
| Zyxel | Pm5100-T0 Firmware | n/a |
| |||||||||
| Zyxel | Pm7300-T0 Firmware | n/a |
| |||||||||
| Zyxel | Pm7500-T0 Firmware | n/a |
| |||||||||
| Zyxel | Px3321-T1 Firmware | n/a |
| |||||||||
| Zyxel | Px5301-T0 Firmware | n/a |
| |||||||||
| Zyxel | Vmg8825-T50k Firmware | n/a |
| |||||||||
| Zyxel | Wx3100-T0 Firmware | n/a |
| |||||||||
| Zyxel | Wx3401-B0 Firmware | n/a |
| |||||||||
| Zyxel | Wx3401-B1 Firmware | n/a |
| |||||||||
| Zyxel | Wx5600-T0 Firmware | n/a |
| |||||||||
| Zyxel | Wx5610-B0 Firmware | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-49603 Advisory
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-buffer-overflow-and-post-authentication-command-injection-vulnerabilities-in-some-4g-lte-5g-nr-cpe-dsl-ethernet-cpe-fiber-onts-and-wifi-extenders-12-03-2024 vendor-advisoryVendor Advisory
Change history (0)
No recorded changes yet.