CVE-2024-38266
24.09.2024, 02:15
An improper restriction of operations within the bounds of a memory buffer in the parameter type parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 could allow an authenticated attacker with administrator privileges to cause potential memory corruptions, resulting in a thread crash on an affected device.Enginsight
Vendor | Product | Version |
---|---|---|
zyxel | dx3300-t0_firmware | 𝑥 < 5.50\(abvy.5\)c0 |
zyxel | dx3300-t1_firmware | 𝑥 < 5.50\(abvy.5\)c0 |
zyxel | dx3301-t0_firmware | 𝑥 < 5.50\(abvy.5\)c0 |
zyxel | dx4510-b0_firmware | 𝑥 < 5.17\(abyl.6\)c0 |
zyxel | dx4510-b1_firmware | 𝑥 < 5.17\(abyl.6\)c0 |
zyxel | dx5401-b0_firmware | 𝑥 < 5.17\(abyo.6\)c0 |
zyxel | dx5401-b1_firmware | 𝑥 < 5.17\(abyo.6\)c0 |
zyxel | ex3300-t0_firmware | 𝑥 < 5.50\(abvy.5\)c0 |
zyxel | ex3300-t1_firmware | 𝑥 < 5.50\(abvy.5\)c0 |
zyxel | ex3301-t0_firmware | 𝑥 < 5.50\(abvy.5\)c0 |
zyxel | ex3500-t0_firmware | 𝑥 < 5.44\(achr.1\)c0 |
zyxel | ex3501-t0_firmware | 𝑥 < 5.44\(achr.1\)c0 |
zyxel | ex3510-b0_firmware | 𝑥 < 5.17\(abup.11\)c0 |
zyxel | ex3510-b1_firmware | 𝑥 < 5.17\(abup.11\)c0 |
zyxel | ex3600-t0_firmware | 𝑥 < 5.70\(acif.0.2\)c0 |
zyxel | ex5401-b0_firmware | 𝑥 < 5.17\(abyo.6\)c0 |
zyxel | ex5401-b1_firmware | 𝑥 < 5.17\(abyo.6\)c0 |
zyxel | ex5510-b0_firmware | 𝑥 < 5.17\(abqx.9\)c0 |
zyxel | ex5512-t0_firmware | 𝑥 < 5.70\(aceg.3\)c1 |
zyxel | ex5601-t0_firmware | 𝑥 < 5.70\(acdz.3\)c0 |
zyxel | ex5601-t1_firmware | 𝑥 < 5.70\(acdz.3\)c0 |
zyxel | ex7501-b0_firmware | 𝑥 < 5.18\(achn.1\)c0 |
zyxel | ex7710-b0_firmware | 𝑥 < 5.18\(acak.1\)c0 |
zyxel | emg3525-t50b_firmware | 𝑥 < 5.50\(abpm.9\)c0 |
zyxel | emg5523-t50b_firmware | 𝑥 < 5.50\(abpm.9\)c0 |
zyxel | emg5723-t50k_firmware | 𝑥 < 5.50\(abom.8\)c0 |
zyxel | vmg3625-t50b_firmware | 𝑥 < 5.50\(abpm.9\)c0 |
zyxel | vmg3927-t50k_firmware | 𝑥 < 5.50\(abom.8\)c0 |
zyxel | vmg4005-b50a_firmware | 𝑥 < 5.17\(abqa.2\)c0 |
zyxel | vmg4005-b60a_firmware | 𝑥 < 5.17\(abqa.2\)c0 |
zyxel | vmg8623-t50b_firmware | 𝑥 < 5.50\(abpm.9\)c0 |
zyxel | vmg8825-t50k_firmware | 𝑥 < 5.50\(abom.8\)c0 |
zyxel | vmg8825-t50k_firmware | 𝑥 < 5.50\(abpy.1\)b24 |
zyxel | ax7501-b0_firmware | 𝑥 < 5.17\(abpc.5\)c0 |
zyxel | ax7501-b1_firmware | 𝑥 < 5.17\(abpc.5\)c0 |
zyxel | pm3100-t0_firmware | 𝑥 < 5.42\(acbf.2\)c0 |
zyxel | pm5100-t0_firmware | 𝑥 < 5.42\(acbf.2\)c0 |
zyxel | pm7300-t0_firmware | 𝑥 < 5.42\(abyy.2.1\)c0 |
zyxel | px3321-t1_firmware | 𝑥 < 5.44\(acjb.0\)c0 |
zyxel | scr50axe_firmware | 𝑥 < 1.10\(acgn.3\)c0 |
zyxel | wx3100-t0_firmware | 𝑥 < 5.50\(abvl.4.3\)c0 |
zyxel | wx3401-b0_firmware | 𝑥 < 5.17\(abve.2.5\)c0 |
zyxel | wx5600-t0_firmware | 𝑥 < 5.70\(aceb.3.2\)c0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-119 - Improper Restriction of Operations within the Bounds of a Memory BufferThe software performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.
- CWE-787 - Out-of-bounds WriteThe software writes data past the end, or before the beginning, of the intended buffer.