Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xf8q-6qq2-4pq3

Опубликовано: 03 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

A post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B firmware versions through V5.50(ABPM.9.2)C0 could allow an authenticated attacker with administrator privileges to cause a temporary denial of service (DoS) condition against the web management interface by sending a crafted HTTP GET request to a vulnerable device if the function ZyEE is enabled.

A post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B firmware versions through V5.50(ABPM.9.2)C0 could allow an authenticated attacker with administrator privileges to cause a temporary denial of service (DoS) condition against the web management interface by sending a crafted HTTP GET request to a vulnerable device if the function ZyEE is enabled.

EPSS

Процентиль: 59%
0.00386
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 4.9
nvd
около 1 года назад

A post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B firmware versions through V5.50(ABPM.9.2)C0 could allow an authenticated attacker with administrator privileges to cause a temporary denial of service (DoS) condition against the web management interface by sending a crafted HTTP GET request to a vulnerable device if the function ZyEE is enabled.

EPSS

Процентиль: 59%
0.00386
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-120