CVE-2024-8748

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
03/12/2024
Last modified:
21/01/2025

Description

A buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmware versions through V5.50(ABOM.8.4)C0 could allow an attacker to cause a temporary denial of service (DoS) condition against the web management interface by sending a crafted HTTP POST request to a vulnerable device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:zyxel:lte3301-plus_firmware:*:*:*:*:*:*:*:* 1.00\(abqu.6\)c0 (excluding)
cpe:2.3:h:zyxel:lte3301-plus:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:lte5388-m804_firmware:*:*:*:*:*:*:*:* 1.00\(absq.5\)c0 (excluding)
cpe:2.3:h:zyxel:lte5388-m804:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:lte5398-m904_firmware:*:*:*:*:*:*:*:* 1.00\(abq.5\)c0 (excluding)
cpe:2.3:h:zyxel:lte5398-m904:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:lte7480-m804_firmware:*:*:*:*:*:*:*:* 1.00\(abra.10\)c0 (excluding)
cpe:2.3:h:zyxel:lte7480-m804:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:lte7490-m904_firmware:*:*:*:*:*:*:*:* 1.00\(abqy.9\)c0 (excluding)
cpe:2.3:h:zyxel:lte7490-m904:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:nr7101_firmware:*:*:*:*:*:*:*:* 1.00\(abu.11\)c0 (excluding)
cpe:2.3:h:zyxel:nr7101:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:nr7102_firmware:*:*:*:*:*:*:*:* 1.00\(abyd.4\)c0 (excluding)
cpe:2.3:h:zyxel:nr7102:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:nebula_nr5101_firmware:*:*:*:*:*:*:*:* 1.16\(accg.1\)c0 (excluding)