HIGH · 7.5

CVE-2024-5412

A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenticated attacker to cause denial of service (DoS) conditions...

Vulnerability Description

A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenticated attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
ZyxelNebula Lte3301-Plus Firmware< 1.18\(acca.4\)c0
ZyxelNebula Lte3301-Plus-
ZyxelNebula Fwa505 Firmware< 1.18\(acko.4\)c0
ZyxelNebula Fwa505-
ZyxelNebula Fwa710 Firmware< 1.18\(acgc.4\)c0
ZyxelNebula Fwa710-
ZyxelNebula Fwa510 Firmware< 1.18\(acgd.4\)c0
ZyxelNebula Fwa510-
ZyxelWx5600-T0 Firmware< 5.70\(aceb.3.2\)c0
ZyxelWx5600-T0-
ZyxelWx3401-B0 Firmware< 5.17\(abve.2.5\)c0
ZyxelWx3401-B0-
ZyxelWx3100-T0 Firmware< 5.50\(abvl.4.2\)c0
ZyxelWx3100-T0-
ZyxelScr50Axe Firmware< 1.10\(acgn.3\)c0
ZyxelScr 50Axe-
ZyxelPx3321-T1 Firmware< 5.44\(acjb.0.2\)z0
ZyxelPx3321-T1-
ZyxelPm7300-T0 Firmware< 5.42\(abyy.2.2\)c0
ZyxelPm7300-T0-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-5412?

CVE-2024-5412 is a vulnerability with a CVSS score of 7.5 (HIGH). A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenticated attacker to cause denial of service (DoS) conditions...

How severe is CVE-2024-5412?

CVE-2024-5412 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-5412?

Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Nebula Lte3301-Plus Firmware, Zyxel Nebula Lte3301-Plus, Zyxel Nebula Fwa505 Firmware, Zyxel Nebula Fwa505, Zyxel Nebula Fwa710 Firmware.