PT-2024-7281 · Zyxel · Zyxel Vmg8825-T50K

Dawid Kulikowski

·

Published

2024-09-23

·

Updated

2026-02-24

·

CVE-2024-38268

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0
Description: The issue is related to an improper restriction of operations within the bounds of a memory buffer in the MAC address parser, which could allow an authenticated attacker with administrator privileges to cause potential memory corruptions. This may result in a thread crash on an affected device. The vulnerability can be exploited by a remote attacker, potentially leading to a denial of service.
Recommendations: For Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0, update to a version that fixes the improper restriction of operations within the bounds of a memory buffer in the MAC address parser to prevent potential memory corruptions and thread crashes. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-08635
CVE-2024-38268

Affected Products

Zyxel Vmg8825-T50K