CVE-2025-7673

A buffer overflow vulnerability in the URL parser of the zhttpd web server in Zyxel VMG8825-T50K firmware versions prior to V5.50(ABOM.5)C0 could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and potentially execute arbitrary code by sending a specially crafted HTTP request.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ZyxelCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 65%
VendorProductVersion
zyxelemg3525-t50b_firmware
𝑥
< 5.50\(abpm.4\)c0
zyxelemg3525-t50b_firmware
𝑥
< 5.50\(absl.0\)b8
zyxelemg5523-t50b_firmware
𝑥
< 5.50\(abpm.4\)c0
zyxelemg5523-t50b_firmware
𝑥
< 5.50\(absl.0\)b8
zyxelemg5723-t50k_firmware
𝑥
< 5.50\(abom.5\)c0
zyxelemg6726-b10a_firmware
𝑥
< 5.13\(abnp.6\).c
zyxelex3510-b0_firmware
𝑥
< 5.17\(abup.3\)c0
zyxelex5510-b0_firmware
𝑥
< 5.15\(abqx.3\)c0
zyxelvmg1312-t20b_firmware
𝑥
< 5.50\(absb.3\)c0
zyxelvmg3625-t50b_firmware
𝑥
< 5.50\(abpm.4\)c0
zyxelvmg3925-b10b_firmware
𝑥
< 5.13\(aavf.16\)c
zyxelvmg3925-b10c_firmware
𝑥
< 5.13\(aavf.16\)c
zyxelvmg3927-b50a_firmware
𝑥
< 5.15\(abmt.5\)c0
zyxelvmg3927-b60a_firmware
𝑥
< 5.15\(abmt.5\)c0
zyxelvmg3927-b50b_firmware
𝑥
< 5.13\(ably.6\)c0
zyxelvmg3927-t50k_firmware
𝑥
< 5.50\(abom.5\)c0
zyxelvmg4005-b50b_firmware
𝑥
< 5.13\(abrl.5\)c0
zyxelvmg4927-b50a_firmware
𝑥
< 5.13\(ably.6\)c0
zyxelvmg8623-t50b_firmware
𝑥
< 5.50\(abpm.4\)c0
zyxelvmg8825-b50a_firmware
𝑥
< 5.15\(abmt.5\)c0
zyxelvmg8825-b60a_firmware
𝑥
< 5.15\(abmt.5\)c0
zyxelvmg8825-bx0b_firmware
𝑥
< 5.17\(abny.5\)c0
zyxelvmg8825-t50k_firmware
𝑥
< 5.50\(abom.5\)c0
zyxelvmg8924-b10d_firmware
𝑥
< 5.13\(abgq.6\)c0
zyxelxmg3927-b50a_firmware
𝑥
< 5.15\(abmt.5\)c0
zyxelxmg8825-b50a_firmware
𝑥
< 5.17\(abmt.5\)c0
𝑥
= Vulnerable software versions