Vulnerability Details CVE-2020-25014
A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted http packet.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.02
EPSS Ranking 82.6%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2020-25014
-
cpe:2.3:h:zyxel:nwa110ax:-
-
cpe:2.3:h:zyxel:nwa1123-ac_hd:-
-
cpe:2.3:h:zyxel:nwa1123-ac_pro:-
-
cpe:2.3:h:zyxel:nwa1123-acv2:-
-
cpe:2.3:h:zyxel:nwa1302-ac:-
-
cpe:2.3:h:zyxel:nwa210ax:-
-
cpe:2.3:h:zyxel:nwa5120:-
-
cpe:2.3:h:zyxel:nwa5301-nj:-
-
cpe:2.3:h:zyxel:usg1100:-
-
-
cpe:2.3:h:zyxel:usg1900:-
-
cpe:2.3:h:zyxel:usg20-vpn:-
-
cpe:2.3:h:zyxel:usg20w-vpn:-
-
-
cpe:2.3:h:zyxel:usg2200-vpn:-
-
-
-
-
-
-
cpe:2.3:h:zyxel:usg_1100:-
-
cpe:2.3:h:zyxel:usg_110:-
-
cpe:2.3:h:zyxel:usg_1900:-
-
cpe:2.3:h:zyxel:usg_20w-vpn:-
-
cpe:2.3:h:zyxel:usg_20w:-
-
cpe:2.3:h:zyxel:usg_2200-vpn:-
-
cpe:2.3:h:zyxel:usg_310:-
-
-
cpe:2.3:h:zyxel:usg_40w:-
-
-
cpe:2.3:h:zyxel:usg_60w:-
-
cpe:2.3:h:zyxel:usg_flex_100:-
-
cpe:2.3:h:zyxel:usg_flex_100w:-
-
cpe:2.3:h:zyxel:usg_flex_200:-
-
cpe:2.3:h:zyxel:usg_flex_500:-
-
cpe:2.3:h:zyxel:usg_flex_700:-
-
-
-
-
cpe:2.3:h:zyxel:wac5302d-s:-
-
cpe:2.3:h:zyxel:wac6100:-
-
cpe:2.3:h:zyxel:wac6303d-s:-
-
cpe:2.3:h:zyxel:wac6500:-
-
cpe:2.3:h:zyxel:wac6550:-
-
cpe:2.3:h:zyxel:wax510d:-
-
cpe:2.3:h:zyxel:wax610d:-
-
cpe:2.3:h:zyxel:wax650s:-
-
cpe:2.3:h:zyxel:zywall_1100:-
-
cpe:2.3:h:zyxel:zywall_110:-
-
cpe:2.3:h:zyxel:zywall_310:-
-
cpe:2.3:o:zyxel:access_points_firmware:-
-
cpe:2.3:o:zyxel:access_points_firmware:6.10
-
-
-
-
-