CVE-2024-8748
Severity CVSS v4.0:
Pending analysis
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
03/12/2024
Last modified:
21/01/2025
Description
A buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmware versions through V5.50(ABOM.8.4)C0 could allow an attacker to cause a temporary denial of service (DoS) condition against the web management interface by sending a crafted HTTP POST request to a vulnerable device.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:zyxel:lte3301-plus_firmware:*:*:*:*:*:*:*:* | 1.00\(abqu.6\)c0 (excluding) | |
| cpe:2.3:h:zyxel:lte3301-plus:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:lte5388-m804_firmware:*:*:*:*:*:*:*:* | 1.00\(absq.5\)c0 (excluding) | |
| cpe:2.3:h:zyxel:lte5388-m804:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:lte5398-m904_firmware:*:*:*:*:*:*:*:* | 1.00\(abq.5\)c0 (excluding) | |
| cpe:2.3:h:zyxel:lte5398-m904:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:lte7480-m804_firmware:*:*:*:*:*:*:*:* | 1.00\(abra.10\)c0 (excluding) | |
| cpe:2.3:h:zyxel:lte7480-m804:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:lte7490-m904_firmware:*:*:*:*:*:*:*:* | 1.00\(abqy.9\)c0 (excluding) | |
| cpe:2.3:h:zyxel:lte7490-m904:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:nr7101_firmware:*:*:*:*:*:*:*:* | 1.00\(abu.11\)c0 (excluding) | |
| cpe:2.3:h:zyxel:nr7101:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:nr7102_firmware:*:*:*:*:*:*:*:* | 1.00\(abyd.4\)c0 (excluding) | |
| cpe:2.3:h:zyxel:nr7102:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:nebula_nr5101_firmware:*:*:*:*:*:*:*:* | 1.16\(accg.1\)c0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



