CVE-2024-8748
high-risk
Published 2024-12-03
A buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmware versions through V5.50(ABOM.8.4)C0 could allow an attacker to cause a temporary denial of service (DoS) condition against the web management interface by sending a crafted HTTP POST request to a vulnerable device.
Do I need to act?
-
0.73% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
NETWORK
/ LOW complexity
Affected Products (20)
Lte3301-Plus Firmware
Lte5388-M804 Firmware
Lte5398-M904 Firmware
Lte7480-M804 Firmware
Lte7490-M904 Firmware
Nr7101 Firmware
Nr7102 Firmware
Nebula Nr5101 Firmware
Nebula Nr7101 Firmware
Nebula Lte3301-Plus Firmware
Dx3300-T0 Firmware
Dx3300-T1 Firmware
Dx4510-B0 Firmware
Dx4510-B1 Firmware
Dx5401-B1 Firmware
Ee6510-10 Firmware
Ex2210-T0 Firmware
Ex3300-T0 Firmware
Affected Vendors
References (1)
55
/ 100
high-risk
Severity
26/34 · High
Exploitability
2/34 · Minimal
Exposure
27/34 · High