CVE-2020-25014: Buffer Overflow
A stack-based buffer overflow in fbwificontinue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted http packet.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-25014?
CVE-2020-25014 is a stack-based buffer overflow vulnerability found in the Zyxel UTM and VPN series of gateways firmware version V4.30 through to V4.55.
How severe is CVE-2020-25014?
CVE-2020-25014 has a severity rating of 9.8 (critical).
How can remote unauthenticated attackers exploit CVE-2020-25014?
Remote unauthenticated attackers can exploit CVE-2020-25014 by sending a crafted HTTP packet, which can allow them to execute arbitrary code.
Which Zyxel devices are affected by CVE-2020-25014?
Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 are affected by CVE-2020-25014.
How can I fix CVE-2020-25014?
To fix CVE-2020-25014, Zyxel has released a security advisory and patches that should be applied to the affected devices. Please refer to the Zyxel support website for more information.