CVE-2023-37929

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
21/05/2024
Last modified:
22/01/2025

Description

The buffer overflow vulnerability in the CGI program of the VMG3625-T50B firmware version V5.50(ABPM.8)C0 could allow an authenticated remote attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:zyxel:dx3300-t1_firmware:5.50\(aby.4\)c0:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:dx3300-t1:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:dx3301-t0_firmware:5.50\(aby.4\)c0:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:dx3301-t0:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:dx4510_firmware:5.17\(abyl.5\)c0:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:dx4510:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:dx5401-b0_firmware:5.17\(abyo.5\)c0:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:dx5401-b0:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:dx5401-b1_firmware:5.17\(abyo.5\)c0:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:dx5401-b1:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:emg3525-t50b_firmware:5.50\(abpm.8\)c0:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:emg3525-t50b:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:emg5523-t50b_firmware:5.50\(abpm.8\)c0:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:emg5523-t50b:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:emg5723-t50k_firmware:5.50\(abom.8.2\)c0:*:*:*:*:*:*:*