nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-7673 CVE-2025-7673
CRITICAL
Zyxel emg3525-t50b_firmware Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Record summary
CVE-2025-7673 has a selected CVSS score of 9.8 (critical).
Description
A buffer overflow vulnerability in the URL parser of the zhttpd web server in Zyxel VMG8825-T50K firmware versions prior to V5.50(ABOM.5)C0 could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and potentially execute arbitrary code by sending a specially crafted HTTP request.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 16, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 19, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
CPE zhttpd WebserverBrowse Zyxel / CPE zhttpd Webserver | VulnCheck | Version data not supplied | |
VMG8825-T50K firmwareBrowse Zyxel / VMG8825-T50K firmwareDefault status: unaffected | CVE List | < V5.50(ABOM.5)C0 | affected |
References
2zyxel.comVendor advisory
https://www.zyxel.com/service-provider/global/en/zyxel-security-advisory-remote-code-execution-and-denial-service-vulnerabilities-cpe