CVE-2024-5412

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
03/09/2024
Last modified:
24/02/2026

Description

A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenticated attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:zyxel:nebula_lte3301-plus_firmware:*:*:*:*:*:*:*:* 1.18\(acca.4\)c0 (excluding)
cpe:2.3:h:zyxel:nebula_lte3301-plus:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:nebula_fwa505_firmware:*:*:*:*:*:*:*:* 1.18\(acko.4\)c0 (excluding)
cpe:2.3:h:zyxel:nebula_fwa505:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:nebula_fwa710_firmware:*:*:*:*:*:*:*:* 1.18\(acgc.4\)c0 (excluding)
cpe:2.3:h:zyxel:nebula_fwa710:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:nebula_fwa510_firmware:*:*:*:*:*:*:*:* 1.18\(acgd.4\)c0 (excluding)
cpe:2.3:h:zyxel:nebula_fwa510:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:wx5600-t0_firmware:*:*:*:*:*:*:*:* 5.70\(aceb.3.2\)c0 (excluding)
cpe:2.3:h:zyxel:wx5600-t0:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:wx3401-b0_firmware:*:*:*:*:*:*:*:* 5.17\(abve.2.5\)c0 (excluding)
cpe:2.3:h:zyxel:wx3401-b0:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:wx3100-t0_firmware:*:*:*:*:*:*:*:* 5.50\(abvl.4.2\)c0 (excluding)
cpe:2.3:h:zyxel:wx3100-t0:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:scr50axe_firmware:*:*:*:*:*:*:*:* 1.10\(acgn.3\)c0 (excluding)