← Back to CVE List
Vulnerability Intelligence Report

CVE-2020-25014

A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted http packet.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:4.26%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
zyxel zld all
zyxel zywall_110 all
zyxel zywall_1100 all
zyxel zywall_310 all
zyxel usg_110 all
zyxel usg_1100 all
zyxel usg_1900 all
zyxel usg_20w all
zyxel usg_20w-vpn all
zyxel usg_2200-vpn all
zyxel usg_310 all
zyxel usg_40 all
zyxel usg_40w all
zyxel usg_60 all
zyxel usg_60w all
zyxel usg110 all
zyxel usg1100 all
zyxel usg1900 all
zyxel usg20-vpn all
zyxel usg20w-vpn all
zyxel usg210 all
zyxel usg2200-vpn all
zyxel usg310 all
zyxel usg40 all
zyxel usg40w all
zyxel usg60 all
zyxel usg60w all
zyxel vpn100 all
zyxel vpn300 all
zyxel vpn50 all
zyxel usg_flex_100 all
zyxel usg_flex_200 all
zyxel usg_flex_500 all
zyxel usg_flex_100w all
zyxel usg_flex_700 all
zyxel access_points_firmware 6.10
zyxel nwa1123-ac_hd all
zyxel nwa1123-ac_pro all
zyxel nwa1123-acv2 all
zyxel wax510d all
zyxel wac5302d-s all
zyxel nwa5120 all
zyxel nwa5301-nj all
zyxel wax610d all
zyxel wax650s all
zyxel wac6550 all
zyxel wac6303d-s all
zyxel wac6500 all
zyxel wac6100 all
zyxel nwa210ax all
zyxel nwa110ax all
zyxel nwa1302-ac all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
4.256%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2020-08-28T00:00:00
Published2020-11-27T17:18:30
Last Updated2024-08-04T15:26:09

LINK COPIED TO CLIPBOARD