A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted http packet.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Zyxel
Subscribe
|
Access Points Firmware
Subscribe
Nwa110ax
Subscribe
Nwa1123-ac Hd
Subscribe
Nwa1123-ac Pro
Subscribe
Nwa1123-acv2
Subscribe
Nwa1302-ac
Subscribe
Nwa210ax
Subscribe
Nwa5120
Subscribe
Nwa5301-nj
Subscribe
Usg110
Subscribe
Usg1100
Subscribe
Usg1900
Subscribe
Usg20-vpn
Subscribe
Usg20w-vpn
Subscribe
Usg210
Subscribe
Usg2200-vpn
Subscribe
Usg310
Subscribe
Usg40
Subscribe
Usg40w
Subscribe
Usg60
Subscribe
Usg60w
Subscribe
Usg 110
Subscribe
Usg 1100
Subscribe
Usg 1900
Subscribe
Usg 20w
Subscribe
Usg 20w-vpn
Subscribe
Usg 2200-vpn
Subscribe
Usg 310
Subscribe
Usg 40
Subscribe
Usg 40w
Subscribe
Usg 60
Subscribe
Usg 60w
Subscribe
Usg Flex 100
Subscribe
Usg Flex 100w
Subscribe
Usg Flex 200
Subscribe
Usg Flex 500
Subscribe
Usg Flex 700
Subscribe
Vpn100
Subscribe
Vpn300
Subscribe
Vpn50
Subscribe
Wac5302d-s
Subscribe
Wac6100
Subscribe
Wac6303d-s
Subscribe
Wac6500
Subscribe
Wac6550
Subscribe
Wax510d
Subscribe
Wax610d
Subscribe
Wax650s
Subscribe
Zld
Subscribe
Zywall 110
Subscribe
Zywall 1100
Subscribe
Zywall 310
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-17714 | A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted http packet. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 12 Dec 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zyxel zld
|
|
| CPEs | cpe:2.3:o:zyxel:zld:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zyxel zld Firmware
|
Zyxel zld
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T15:26:09.045Z
Reserved: 2020-08-28T00:00:00
Link: CVE-2020-25014
No data.
Status : Modified
Published: 2020-11-27T18:15:11.563
Modified: 2024-12-12T16:23:25.593
Link: CVE-2020-25014
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD