CVE-2025-7673
Last modified
CVE-2025-7673 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A buffer overflow vulnerability in the URL parser of the zhttpd web server in Zyxel VMG8825-T50K firmware versions prior to V5.50(ABOM.5)C0 could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and potentially execute arbitrary code by sending a specially crafted HTTP request.. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
A buffer overflow vulnerability in the URL parser of the zhttpd web server in Zyxel VMG8825-T50K firmware versions prior to V5.50(ABOM.5)C0 could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and potentially execute arbitrary code by sending a specially crafted HTTP request.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zyxel | Emg3525-T50b Firmware | < 5.50\(abpm.4\)c0 |
| Zyxel | Emg3525-T50b Firmware | < 5.50\(absl.0\)b8 |
| Zyxel | Emg5523-T50b Firmware | < 5.50\(abpm.4\)c0 |
| Zyxel | Emg5523-T50b Firmware | < 5.50\(absl.0\)b8 |
| Zyxel | Emg5723-T50k Firmware | < 5.50\(abom.5\)c0 |
| Zyxel | Emg6726-B10a Firmware | < 5.13\(abnp.6\).c |
| Zyxel | Ex3510-B0 Firmware | < 5.17\(abup.3\)c0 |
| Zyxel | Ex5510-B0 Firmware | < 5.15\(abqx.3\)c0 |
| Zyxel | Vmg1312-T20b Firmware | < 5.50\(absb.3\)c0 |
| Zyxel | Vmg3625-T50b Firmware | < 5.50\(abpm.4\)c0 |
| Zyxel | Vmg3925-B10b Firmware | < 5.13\(aavf.16\)c |
| Zyxel | Vmg3925-B10c Firmware | < 5.13\(aavf.16\)c |
| Zyxel | Vmg3927-B50a Firmware | < 5.15\(abmt.5\)c0 |
| Zyxel | Vmg3927-B60a Firmware | < 5.15\(abmt.5\)c0 |
| Zyxel | Vmg3927-B50b Firmware | < 5.13\(ably.6\)c0 |
| Zyxel | Vmg3927-T50k Firmware | < 5.50\(abom.5\)c0 |
| Zyxel | Vmg4005-B50b Firmware | < 5.13\(abrl.5\)c0 |
| Zyxel | Vmg4927-B50a Firmware | < 5.13\(ably.6\)c0 |
| Zyxel | Vmg8623-T50b Firmware | < 5.50\(abpm.4\)c0 |
| Zyxel | Vmg8825-B50a Firmware | < 5.15\(abmt.5\)c0 |
| Zyxel | Vmg8825-B60a Firmware | < 5.15\(abmt.5\)c0 |
| Zyxel | Vmg8825-Bx0b Firmware | < 5.17\(abny.5\)c0 |
| Zyxel | Vmg8825-T50k Firmware | < 5.50\(abom.5\)c0 |
| Zyxel | Vmg8924-B10d Firmware | < 5.13\(abgq.6\)c0 |
| Zyxel | Xmg3927-B50a Firmware | < 5.15\(abmt.5\)c0 |
| Zyxel | Xmg8825-B50a Firmware | < 5.17\(abmt.5\)c0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-7673?
How severe is CVE-2025-7673?
How do I fix CVE-2025-7673?
Are you affected by CVE-2025-7673?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
