A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted http packet.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://businessforum.zyxel.com/categories/security-news-and-release | release notes vendor advisory |
https://www.zyxel.com/support/Zyxel-security-advisory-for-buffer-overflow-vulnerability.shtml | vendor advisory |