CVE-2023-37929

MEDIUM
Published May 21, 2024 Modified Jan 22, 2025 CWE-120

Description

The buffer overflow vulnerability in the CGI program of the VMG3625-T50B firmware version V5.50(ABPM.8)C0 could allow an authenticated remote attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device.

Is your site exposed to CVE-2023-37929?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

6.5
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Weakness Type (CWE)

CWE-120 CWE-120

Affected Products

Vendor Product
zyxel dx3300-t1_firmware
zyxel dx3300-t1
zyxel dx3301-t0_firmware
zyxel dx3301-t0
zyxel dx4510_firmware
zyxel dx4510
zyxel dx5401-b0_firmware
zyxel dx5401-b0
zyxel dx5401-b1_firmware
zyxel dx5401-b1
zyxel emg3525-t50b_firmware
zyxel emg3525-t50b
zyxel emg5523-t50b_firmware
zyxel emg5523-t50b
zyxel emg5723-t50k_firmware
zyxel emg5723-t50k
zyxel ex3300-t1_firmware
zyxel ex3300-t1
zyxel ex3301-t0_firmware
zyxel ex3301-t0
zyxel ex3500-t0_firmware
zyxel ex3500-t0
zyxel ex3501-t0_firmware
zyxel ex3501-t0
zyxel ex3510_firmware
zyxel ex3510
zyxel ex5401-b0_firmware
zyxel ex5401-b0
zyxel ex5401-b1_firmware
zyxel ex5401-b1
zyxel ex5501-b0_firmware
zyxel ex5501-b0
zyxel ex5510_firmware
zyxel ex5510
zyxel ex5512-t0_firmware
zyxel ex5512-t0
zyxel ex5600-t1_firmware
zyxel ex5600-t1
zyxel ex5601-t0_firmware
zyxel ex5601-t0
zyxel ex5601-t1_firmware
zyxel ex5601-t1
zyxel ex7710-b0_firmware
zyxel ex7710-b0
zyxel vmg3625-t50b_firmware
zyxel vmg3625-t50b
zyxel vmg3927-t50k_firmware
zyxel vmg3927-t50k
zyxel vmg8623-t50b_firmware
zyxel vmg8623-t50b
zyxel vmg8825-t50k_firmware
zyxel vmg8825-t50k
zyxel ax7501-b0_firmware
zyxel ax7501-b0
zyxel ax7501-b1_firmware
zyxel ax7501-b1
zyxel wx3100-t0_firmware
zyxel wx3100-t0
zyxel wx5600-t0_firmware
zyxel wx5600-t0
zyxel wx5610-b0_firmware
zyxel wx5610-b0
zyxel nbg7510_firmware
zyxel nbg7510

References

Frequently Asked Questions

What is CVE-2023-37929? +
The buffer overflow vulnerability in the CGI program of the VMG3625-T50B firmware version V5.50(ABPM.8)C0 could allow an authenticated remote attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device. It has a CVSS v3.1 base score of 6.5 (MEDIUM).
How severe is CVE-2023-37929? +
CVE-2023-37929 has a CVSS v3.1 score of 6.5 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2023-37929? +
CVE-2023-37929 affects products from zyxel, specifically: ax7501-b0, ax7501-b0_firmware, ax7501-b1, ax7501-b1_firmware, dx3300-t1, dx3300-t1_firmware, dx3301-t0, dx3301-t0_firmware, dx4510, dx4510_firmware, dx5401-b0, dx5401-b0_firmware, dx5401-b1, dx5401-b1_firmware, emg3525-t50b, emg3525-t50b_firmware, emg5523-t50b, emg5523-t50b_firmware, emg5723-t50k, emg5723-t50k_firmware, ex3300-t1, ex3300-t1_firmware, ex3301-t0, ex3301-t0_firmware, ex3500-t0, ex3500-t0_firmware, ex3501-t0, ex3501-t0_firmware, ex3510, ex3510_firmware, ex5401-b0, ex5401-b0_firmware, ex5401-b1, ex5401-b1_firmware, ex5501-b0, ex5501-b0_firmware, ex5510, ex5510_firmware, ex5512-t0, ex5512-t0_firmware, ex5600-t1, ex5600-t1_firmware, ex5601-t0, ex5601-t0_firmware, ex5601-t1, ex5601-t1_firmware, ex7710-b0, ex7710-b0_firmware, nbg7510, nbg7510_firmware, vmg3625-t50b, vmg3625-t50b_firmware, vmg3927-t50k, vmg3927-t50k_firmware, vmg8623-t50b, vmg8623-t50b_firmware, vmg8825-t50k, vmg8825-t50k_firmware, wx3100-t0, wx3100-t0_firmware, wx5600-t0, wx5600-t0_firmware, wx5610-b0, wx5610-b0_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2023-37929? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2023-37929 — free, no signup required.