CVE-2020-25014
9.8
CRITICAL · CVSS 3.1 · EPSS 4.4% (pctl 91)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted http packet.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.44% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-787 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-11-27 |
| Last modified | 2026-06-17 |
Affected (40)
| Vendor | Product |
|---|---|
| zyxel | access points firmware |
| zyxel | nwa1123-ac hd |
| zyxel | nwa1123-ac pro |
| zyxel | nwa1123-acv2 |
| zyxel | usg 110 |
| zyxel | usg 1100 |
| zyxel | usg 1900 |
| zyxel | usg 20w |
| zyxel | usg 20w-vpn |
| zyxel | usg 2200-vpn |
| zyxel | usg 310 |
| zyxel | usg 40 |
| zyxel | usg 40w |
| zyxel | usg 60 |
| zyxel | usg 60w |
| zyxel | usg flex 100 |
| zyxel | usg flex 100w |
| zyxel | usg flex 200 |
| zyxel | usg flex 500 |
| zyxel | usg flex 700 |
| zyxel | usg110 |
| zyxel | usg1100 |
| zyxel | usg1900 |
| zyxel | usg20-vpn |
| zyxel | usg20w-vpn |
| zyxel | usg210 |
| zyxel | usg2200-vpn |
| zyxel | usg310 |
| zyxel | usg40 |
| zyxel | usg40w |
| zyxel | usg60 |
| zyxel | usg60w |
| zyxel | vpn100 |
| zyxel | vpn300 |
| zyxel | vpn50 |
| zyxel | wax510d |
| zyxel | zld |
| zyxel | zywall 110 |
| zyxel | zywall 1100 |
| zyxel | zywall 310 |
References
- https://businessforum.zyxel.com/categories/security-news-and-release
- https://www.zyxel.com/support/Zyxel-security-advisory-for-buffer-overflow-vulnerability.shtml
- https://businessforum.zyxel.com/categories/security-news-and-release
- https://www.zyxel.com/support/Zyxel-security-advisory-for-buffer-overflow-vulnerability.shtml
→ the Explorer · watch your stack · NVD