PT-2024-7280 · Zyxel · Zyxel Vmg8825-T50K

Dawid Kulikowski

·

Published

2024-09-23

·

Updated

2026-02-24

·

CVE-2024-38267

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0
Description: The issue is related to an improper restriction of operations within the bounds of a memory buffer in the IPv6 address parser. This could allow an authenticated attacker with administrator privileges to cause potential memory corruptions, resulting in a thread crash on an affected device. The vulnerability may also be exploited by a remote attacker to cause a denial of service.
Recommendations: For Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0, update to a version that fixes the improper restriction of operations within the bounds of a memory buffer in the IPv6 address parser. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-08634
CVE-2024-38267

Affected Products

Zyxel Vmg8825-T50K