Critical severity9.8NVD Advisory· Published Nov 27, 2020· Updated Jun 17, 2026
CVE-2020-25014
CVE-2020-25014
Description
A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted http packet.
Affected products
13cpe:2.3:o:zyxel:access_points_firmware:*:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:o:zyxel:access_points_firmware:*:*:*:*:*:*:*:*range: <=6.10
- cpe:2.3:o:zyxel:access_points_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:zyxel:access_points_firmware:6.10:-:*:*:*:*:*:*
- cpe:2.3:o:zyxel:access_points_firmware:6.10:patch1:*:*:*:*:*:*
- cpe:2.3:o:zyxel:access_points_firmware:6.10:patch2:*:*:*:*:*:*
- cpe:2.3:o:zyxel:access_points_firmware:6.10:patch3:*:*:*:*:*:*
- cpe:2.3:o:zyxel:access_points_firmware:6.10:patch4:*:*:*:*:*:*
- cpe:2.3:o:zyxel:access_points_firmware:6.10:patch5:*:*:*:*:*:*
- cpe:2.3:o:zyxel:access_points_firmware:6.10:patch6:*:*:*:*:*:*
- cpe:2.3:o:zyxel:access_points_firmware:6.10:patch7:*:*:*:*:*:*
- Zyxel/UTM and VPN seriesdescription
- Range: V4.30 - V4.55
Patches
Vulnerability mechanics
References
2- businessforum.zyxel.com/categories/security-news-and-releasenvdRelease NotesVendor Advisory
- www.zyxel.com/support/Zyxel-security-advisory-for-buffer-overflow-vulnerability.shtmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.