CVE-2025-6599

HIGHCVSS 7.5/10EPSS 0.27%

Last modified

CVE-2025-6599 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an attacker to perform Slowloris‑style denial‑of‑service (DoS) attacks. Such attacks may temporarily block legitimate HTTP requests and partially disrupt access to the web management interface, while other networking services remain unaffected.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.

Description

An uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an attacker to perform Slowloris‑style denial‑of‑service (DoS) attacks. Such attacks may temporarily block legitimate HTTP requests and partially disrupt access to the web management interface, while other networking services remain unaffected.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
0.27%

19.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
ZyxelLte3301-Plus Firmware<= 1.00\(abqu.7\)c0
ZyxelNr5103 Firmware<= 4.19\(abyc.8\)c0
ZyxelNr5103e Firmware<= 1.00\(acdj.1\)c0
ZyxelNr5309 Firmware<= 1.00\(ackp.1\)b3
ZyxelNr7302 Firmware<= 5.00\(acha.5\)c0
ZyxelNr7303 Firmware<= 1.00\(acei.1\)c0
ZyxelNebula Fwa505 Firmware<= 1.19\(acko.0\)c0
ZyxelNebula Fwa510 Firmware<= 1.20\(acgd.1\)c0
ZyxelNebula Fwa515 Firmware<= 1.50\(acpz.0\)c0
ZyxelNebula Fwa710 Firmware<= 1.20\(acgc.0\)c0
ZyxelDm4200-B0 Firmware<= 5.17\(acbs.1.3\)c0
ZyxelDx3300-T0 Firmware<= 5.50\(abvy.6.3\)c0
ZyxelDx3300-T1 Firmware<= 5.50\(abvy.6.3\)c0
ZyxelDx3301-T0 Firmware<= 5.50\(abvy.6.3\)c0
ZyxelDx4510-B1 Firmware<= 5.17\(abyl.9\)c0
ZyxelDx5401-B0 Firmware<= 5.17\(abyo.7\)b2
ZyxelDx5401-B1 Firmware<= 5.17\(abyo.7\)b2
ZyxelEe3301-00 Firmware<= 5.63\(acmu.1.1\)c0
ZyxelEe5301-00 Firmware<= 5.63\(acld.1.1\)c0
ZyxelEe6510-10 Firmware<= 5.19\(acjq.3\)c0
ZyxelEx3300-T0 Firmware<= 5.50\(abvy.6.3\)c0
ZyxelEx3300-T0 Firmware<= 5.50\(acdi.2.1\)c0
ZyxelEx3300-T1 Firmware<= 5.50\(abvy.6.3\)c0
ZyxelEx3301-T0 Firmware<= 5.50\(abvy.6.3\)c0
ZyxelEx3500-T0 Firmware<= 5.44\(achr.4\)c0
ZyxelEx3501-T0 Firmware<= 5.44\(achr.4\)c0
ZyxelEx3600-T0 Firmware<= 5.70\(acif.1.2\)c0
ZyxelEx5401-B0 Firmware<= 5.17\(abyo.7\)b2
ZyxelEx5401-B1 Firmware<= 5.17\(abyo.7\)b2
ZyxelEx5501-B0 Firmware<= 5.17\(abry.5.5\)c0
ZyxelEx5510-B0 Firmware<= 5.17\(abqx.10\)c0
ZyxelEx5512-T0 Firmware<= 5.70\(aceg.5\)c0
ZyxelEx5601-T0 Firmware<= 5.70\(acdz.4.1\)c0
ZyxelEx5601-T1 Firmware<= 5.70\(acdz.4.1\)c0
ZyxelEx7501-B0 Firmware<= 5.18\(achn.2.1\)c0
ZyxelEx7710-B0 Firmware<= 5.18\(acak.1.4\)c0
ZyxelEmg3525-T50b Firmware<= 5.50\(abpm.9.5\)c0
ZyxelEmg5523-T50b Firmware<= 5.50\(abpm.9.5\)c0
ZyxelEmg5723-T50k Firmware<= 5.50\(abom.8.6\)c0
ZyxelEmg6726-B10a Firmware<= 5.13\(abnp.8\)c0
ZyxelGm4100-B0 Firmware<= 5.18\(accl.1\)c0
ZyxelVmg3625-T50b Firmware<= 5.50\(abpm.9.5\)c0
ZyxelVmg3927-B50b Firmware<= 5.13\(ably.10\)c0
ZyxelVmg3927-T50k Firmware<= 5.50\(abom.8.6\)c0
ZyxelVmg4005-B50a Firmware<= 5.17\(abqa.3\)c0
ZyxelVmg4005-B60a Firmware<= 5.17\(abqa.3\)c0
ZyxelVmg4005-B50b Firmware<= 5.13\(abrl.5.3\)c0
ZyxelVmg4927-B50a Firmware<= 5.13\(ably.10\)c0
ZyxelVmg8623-T50b Firmware<= 5.50\(abpm.9.5\)c0
ZyxelVmg8825-T50k Firmware<= 5.50\(abom.8.6\)c0

Showing 50 of 68 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2025-6599?
An uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an attacker to perform Slowloris‑style denial‑of‑service (DoS) attacks. Such attacks may temporarily block legitimate HTTP requests and partially disrupt access to the web management interface, while other networking services remain unaffected.
How severe is CVE-2025-6599?
CVE-2025-6599 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 0.27% probability of exploitation in the next 30 days.
How do I fix CVE-2025-6599?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2025-6599?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST