A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted http packet.

Project Subscriptions

Vendors Products
Access Points Firmware Subscribe
Nwa110ax Subscribe
Nwa1123-ac Hd Subscribe
Nwa1123-ac Pro Subscribe
Nwa1123-acv2 Subscribe
Nwa1302-ac Subscribe
Nwa210ax Subscribe
Nwa5120 Subscribe
Nwa5301-nj Subscribe
Usg1100 Subscribe
Usg1900 Subscribe
Usg20-vpn Subscribe
Usg20w-vpn Subscribe
Usg2200-vpn Subscribe
Usg 110 Subscribe
Usg 1100 Subscribe
Usg 1900 Subscribe
Usg 20w Subscribe
Usg 20w-vpn Subscribe
Usg 2200-vpn Subscribe
Usg 310 Subscribe
Usg 40w Subscribe
Usg 60w Subscribe
Usg Flex 100 Subscribe
Usg Flex 100w Subscribe
Usg Flex 200 Subscribe
Usg Flex 500 Subscribe
Usg Flex 700 Subscribe
Wac5302d-s Subscribe
Wac6100 Subscribe
Wac6303d-s Subscribe
Wac6500 Subscribe
Wac6550 Subscribe
Wax510d Subscribe
Wax610d Subscribe
Wax650s Subscribe
Zywall 110 Subscribe
Zywall 1100 Subscribe
Zywall 310 Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-17714 A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted http packet.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 12 Dec 2024 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Zyxel zld
CPEs cpe:2.3:o:zyxel:zld_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:zld:*:*:*:*:*:*:*:*
Vendors & Products Zyxel zld Firmware
Zyxel zld

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T15:26:09.045Z

Reserved: 2020-08-28T00:00:00

Link: CVE-2020-25014

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-11-27T18:15:11.563

Modified: 2024-12-12T16:23:25.593

Link: CVE-2020-25014

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses