CVE-2022-26414
Severity CVSS v4.0:
Pending analysis
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
11/04/2022
Last modified:
15/04/2022
Description
A potential buffer overflow vulnerability was identified in some internal functions of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0, which could be exploited by a local authenticated attacker to cause a denial of service.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Base Score 2.0
4.90
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:zyxel:vmg3312-t20a_firmware:5.30\(abfx.5\)c0:*:*:*:*:*:*:* | ||
| cpe:2.3:h:zyxel:vmg3312-t20a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:emg3525-t50b_firmware:*:*:*:*:america:*:*:* | 5.50\(abpm.6\)c0 (excluding) | |
| cpe:2.3:o:zyxel:emg3525-t50b_firmware:*:*:*:*:emea:*:*:* | 5.50\(abpm.6\)c0 (excluding) | |
| cpe:2.3:h:zyxel:emg3525-t50b:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:emg5523-t50b_firmware:*:*:*:*:america:*:*:* | 5.50\(abpm.6\)c0 (excluding) | |
| cpe:2.3:o:zyxel:emg5523-t50b_firmware:*:*:*:*:emea:*:*:* | 5.50\(abpm.6\)c0 (excluding) | |
| cpe:2.3:h:zyxel:emg5523-t50b:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:emg5723-t50k_firmware:*:*:*:*:*:*:*:* | 5.50\(abom.7\)c0 (excluding) | |
| cpe:2.3:h:zyxel:emg5723-t50k:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:emg6726-b10a_firmware:*:*:*:*:*:*:*:* | 5.13\(abnp.7\)c0 (excluding) | |
| cpe:2.3:h:zyxel:emg6726-b10a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:vmg1312-t20b_firmware:*:*:*:*:*:*:*:* | 5.50\(absb.5\)c0 (excluding) | |
| cpe:2.3:h:zyxel:vmg1312-t20b:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:vmg3625-t50b_firmware:*:*:*:*:*:*:*:* | 5.50\(abpm.6\)c0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



