CVE-2024-38266

MEDIUM

Zyxel VMG8825-T50K <5.50(ABOM.8)C0 - Memory Corruption

Title source: llm
STIX 2.1

Description

An improper restriction of operations within the bounds of a memory buffer in the parameter type parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 could allow an authenticated attacker with administrator privileges to cause potential memory corruptions, resulting in a thread crash on an affected device.

Scores

CVSS v3 4.9
EPSS 0.0018
EPSS Percentile 39.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-119 CWE-787
Status published
Products (42)
zyxel/ax7501-b0_firmware < 5.17\(abpc.5\)c0
zyxel/ax7501-b1_firmware < 5.17\(abpc.5\)c0
zyxel/dx3300-t0_firmware < 5.50\(abvy.5\)c0
zyxel/dx3300-t1_firmware < 5.50\(abvy.5\)c0
zyxel/dx3301-t0_firmware < 5.50\(abvy.5\)c0
zyxel/dx4510-b0_firmware < 5.17\(abyl.6\)c0
zyxel/dx4510-b1_firmware < 5.17\(abyl.6\)c0
zyxel/dx5401-b0_firmware < 5.17\(abyo.6\)c0
zyxel/dx5401-b1_firmware < 5.17\(abyo.6\)c0
zyxel/emg3525-t50b_firmware < 5.50\(abpm.9\)c0
... and 32 more
Published Sep 24, 2024
Tracked Since Feb 18, 2026