CVE-2025-7673
A buffer overflow vulnerability in the URL parser of the zhttpd web server in Zyxel VMG8825-T50K firmware versions prior to V5.50(ABOM.5)C0 could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and potentially execute…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.55%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A buffer overflow vulnerability in the URL parser of the zhttpd web server in Zyxel VMG8825-T50K firmware versions prior to V5.50(ABOM.5)C0 could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and potentially execute arbitrary code by sending a specially crafted HTTP request.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.55% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- zyxel/emg3525-t50b firmware · zyxel/emg5523-t50b firmware · zyxel/emg5723-t50k firmware · zyxel/emg6726-b10a firmware · zyxel/ex3510-b0 firmware · zyxel/ex5510-b0 firmware · zyxel/vmg1312-t20b firmware · zyxel/vmg3625-t50b firmware · zyxel/vmg3925-b10b firmware · zyxel/vmg3925-b10c firmware · zyxel/vmg3927-b50a firmware · zyxel/vmg3927-b60a firmware · zyxel/vmg3927-b50b firmware · zyxel/vmg3927-t50k firmware · zyxel/vmg4005-b50b firmware · zyxel/vmg4927-b50a firmware · zyxel/vmg8623-t50b firmware · zyxel/vmg8825-b50a firmware · zyxel/vmg8825-b60a firmware · zyxel/vmg8825-bx0b firmware · +4 more
- Source
- security@zyxel.com.tw
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.