CVE-2024-0816

MEDIUM
Published May 21, 2024 Modified Jan 22, 2025 CWE-120

Description

The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of service (DoS) conditions by executing the CLI command with crafted strings on an affected device.

Is your site exposed to CVE-2024-0816?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

5.5
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Weakness Type (CWE)

CWE-120 CWE-120

Affected Products

Vendor Product
zyxel lte3202-m437_firmware
zyxel lte3202-m437
zyxel lte3301-plus_firmware
zyxel lte3301-plus
zyxel lte5388-m804_firmware
zyxel lte5388-m804
zyxel lte5398-m904_firmware
zyxel lte5398-m904
zyxel lte7240-m403_firmware
zyxel lte7240-m403
zyxel lte7480-m804_firmware
zyxel lte7480-m804
zyxel lte7490-m904_firmware
zyxel lte7490-m904
zyxel nr5103_firmware
zyxel nr5103
zyxel nr5103e_firmware
zyxel nr5103e
zyxel nr5103ev2_firmware
zyxel nr5103ev2
zyxel nr5307_firmware
zyxel nr5307
zyxel nr7101_firmware
zyxel nr7101
zyxel nr7102_firmware
zyxel nr7102
zyxel nr7103_firmware
zyxel nr7103
zyxel nr7302_firmware
zyxel nr7302
zyxel nr7303_firmware
zyxel nr7303
zyxel nr7501_firmware
zyxel nr7501
zyxel nebula_fwa505_firmware
zyxel nebula_fwa505
zyxel nebula_fwa510_firmware
zyxel nebula_fwa510
zyxel nebula_fwa710_firmware
zyxel nebula_fwa710
zyxel nebula_lte3301-plus_firmware
zyxel nebula_lte3301-plus
zyxel nebula_lte7461-m602_firmware
zyxel nebula_lte7461-m602
zyxel nebula_nr5101_firmware
zyxel nebula_nr5101
zyxel nebula_nr7101_firmware
zyxel nebula_nr7101
zyxel dx3300-t1_firmware
zyxel dx3300-t1
zyxel dx3301-t0_firmware
zyxel dx3301-t0
zyxel dx4510_firmware
zyxel dx4510
zyxel dx5401-b0_firmware
zyxel dx5401-b0
zyxel dx5401-b1_firmware
zyxel dx5401-b1
zyxel emg3525-t50b_firmware
zyxel emg3525-t50b
zyxel emg5523-t50b_firmware
zyxel emg5523-t50b
zyxel emg5723-t50k_firmware
zyxel emg5723-t50k
zyxel ex3300-t1_firmware
zyxel ex3300-t1
zyxel ex3301-t0_firmware
zyxel ex3301-t0
zyxel ex3320-t0_firmware
zyxel ex3320-t0
zyxel ex3320-t1_firmware
zyxel ex3320-t1
zyxel ex3500-t0_firmware
zyxel ex3500-t0
zyxel ex3501-t0_firmware
zyxel ex3501-t0
zyxel ex3510_firmware
zyxel ex3510
zyxel ex5401-b0_firmware
zyxel ex5401-b0
zyxel ex5401-b1_firmware
zyxel ex5401-b1
zyxel ex5501-b0_firmware
zyxel ex5501-b0
zyxel ex5510_firmware
zyxel ex5510
zyxel ex5512-t0_firmware
zyxel ex5512-t0
zyxel ex5600-t1_firmware
zyxel ex5600-t1
zyxel ex5601-t0_firmware
zyxel ex5601-t0
zyxel ex5601-t1_firmware
zyxel ex5601-t1
zyxel ex7710-b0_firmware
zyxel ex7710-b0
zyxel vmg3625-t50b_firmware
zyxel vmg3625-t50b
zyxel vmg3927-t50k_firmware
zyxel vmg3927-t50k
zyxel vmg4005-b50a_firmware
zyxel vmg4005-b50a
zyxel vmg4005-b60a_firmware
zyxel vmg4005-b60a
zyxel vmg8623-t50b_firmware
zyxel vmg8623-t50b
zyxel vmg8825-t50k_firmware
zyxel vmg8825-t50k
zyxel ax7501-b0_firmware
zyxel ax7501-b0
zyxel ax7501-b1_firmware
zyxel ax7501-b1
zyxel pm3100-t0_firmware
zyxel pm3100-t0
zyxel pm5100-t0_firmware
zyxel pm5100-t0
zyxel pm7300-t0_firmware
zyxel pm7300-t0
zyxel px3321-t1_firmware
zyxel px3321-t1
zyxel wx3100-t0_firmware
zyxel wx3100-t0
zyxel wx3401-b0_firmware
zyxel wx3401-b0
zyxel wx5600-t0_firmware
zyxel wx5600-t0
zyxel wx5610-b0_firmware
zyxel wx5610-b0
zyxel nbg7510_firmware
zyxel nbg7510

References

Frequently Asked Questions

What is CVE-2024-0816? +
The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of service (DoS) conditions by executing the CLI command with crafted strings on an affected device. It has a CVSS v3.1 base score of 5.5 (MEDIUM).
How severe is CVE-2024-0816? +
CVE-2024-0816 has a CVSS v3.1 score of 5.5 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2024-0816? +
CVE-2024-0816 affects products from zyxel, specifically: ax7501-b0, ax7501-b0_firmware, ax7501-b1, ax7501-b1_firmware, dx3300-t1, dx3300-t1_firmware, dx3301-t0, dx3301-t0_firmware, dx4510, dx4510_firmware, dx5401-b0, dx5401-b0_firmware, dx5401-b1, dx5401-b1_firmware, emg3525-t50b, emg3525-t50b_firmware, emg5523-t50b, emg5523-t50b_firmware, emg5723-t50k, emg5723-t50k_firmware, ex3300-t1, ex3300-t1_firmware, ex3301-t0, ex3301-t0_firmware, ex3320-t0, ex3320-t0_firmware, ex3320-t1, ex3320-t1_firmware, ex3500-t0, ex3500-t0_firmware, ex3501-t0, ex3501-t0_firmware, ex3510, ex3510_firmware, ex5401-b0, ex5401-b0_firmware, ex5401-b1, ex5401-b1_firmware, ex5501-b0, ex5501-b0_firmware, ex5510, ex5510_firmware, ex5512-t0, ex5512-t0_firmware, ex5600-t1, ex5600-t1_firmware, ex5601-t0, ex5601-t0_firmware, ex5601-t1, ex5601-t1_firmware, ex7710-b0, ex7710-b0_firmware, lte3202-m437, lte3202-m437_firmware, lte3301-plus, lte3301-plus_firmware, lte5388-m804, lte5388-m804_firmware, lte5398-m904, lte5398-m904_firmware, lte7240-m403, lte7240-m403_firmware, lte7480-m804, lte7480-m804_firmware, lte7490-m904, lte7490-m904_firmware, nbg7510, nbg7510_firmware, nebula_fwa505, nebula_fwa505_firmware, nebula_fwa510, nebula_fwa510_firmware, nebula_fwa710, nebula_fwa710_firmware, nebula_lte3301-plus, nebula_lte3301-plus_firmware, nebula_lte7461-m602, nebula_lte7461-m602_firmware, nebula_nr5101, nebula_nr5101_firmware, nebula_nr7101, nebula_nr7101_firmware, nr5103, nr5103_firmware, nr5103e, nr5103e_firmware, nr5103ev2, nr5103ev2_firmware, nr5307, nr5307_firmware, nr7101, nr7101_firmware, nr7102, nr7102_firmware, nr7103, nr7103_firmware, nr7302, nr7302_firmware, nr7303, nr7303_firmware, nr7501, nr7501_firmware, pm3100-t0, pm3100-t0_firmware, pm5100-t0, pm5100-t0_firmware, pm7300-t0, pm7300-t0_firmware, px3321-t1, px3321-t1_firmware, vmg3625-t50b, vmg3625-t50b_firmware, vmg3927-t50k, vmg3927-t50k_firmware, vmg4005-b50a, vmg4005-b50a_firmware, vmg4005-b60a, vmg4005-b60a_firmware, vmg8623-t50b, vmg8623-t50b_firmware, vmg8825-t50k, vmg8825-t50k_firmware, wx3100-t0, wx3100-t0_firmware, wx3401-b0, wx3401-b0_firmware, wx5600-t0, wx5600-t0_firmware, wx5610-b0, wx5610-b0_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-0816? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-0816 — free, no signup required.