A post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B firmware versions through V5.50(ABPM.9.2)C0 could allow an authenticated attacker with administrator privileges to cause a temporary denial of service (DoS) condition against the web management interface by sending a crafted HTTP GET request to a vulnerable device if the function ZyEE is enabled.
CVE ID: CVE-2024-9197
CVSS Base Severity: MEDIUM
CVSS Base Score: 4.9
Vendor: Zyxel
Product: VMG3625-T50B firmware
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 15.59% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)