CVE-2024-5412

HIGH
Published Sep 3, 2024 Modified Feb 24, 2026 CWE-120

Description

A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenticated attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device.

Is your site exposed to CVE-2024-5412?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

7.5
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weakness Type (CWE)

CWE-120 CWE-120

Affected Products

Vendor Product
zyxel nebula_lte3301-plus_firmware
zyxel nebula_lte3301-plus
zyxel nebula_fwa505_firmware
zyxel nebula_fwa505
zyxel nebula_fwa710_firmware
zyxel nebula_fwa710
zyxel nebula_fwa510_firmware
zyxel nebula_fwa510
zyxel wx5600-t0_firmware
zyxel wx5600-t0
zyxel wx3401-b0_firmware
zyxel wx3401-b0
zyxel wx3100-t0_firmware
zyxel wx3100-t0
zyxel scr50axe_firmware
zyxel scr_50axe
zyxel px3321-t1_firmware
zyxel px3321-t1
zyxel pm7300-t0_firmware
zyxel pm7300-t0
zyxel pm5100-t0_firmware
zyxel pm5100-t0
zyxel pm3100-t0_firmware
zyxel pm3100-t0
zyxel ax7501-b1_firmware
zyxel ax7501-b1
zyxel ax7501-b0_firmware
zyxel ax7501-b0
zyxel vmg8825-t50k_firmware
zyxel vmg8825-t50k
zyxel vmg8623-t50b_firmware
zyxel vmg8623-t50b
zyxel vmg4005-b60a_firmware
zyxel vmg4005-b60a
zyxel vmg4005-b50a_firmware
zyxel vmg4005-b50a
zyxel vmg3927-t50k_firmware
zyxel vmg3927-t50k
zyxel vmg3625-t50b_firmware
zyxel vmg3625-t50b
zyxel emg5723-t50k_firmware
zyxel emg5723-t50k
zyxel emg5523-t50b_firmware
zyxel emg5523-t50b
zyxel emg3525-t50b_firmware
zyxel emg3525-t50b
zyxel ex7710-b0_firmware
zyxel ex7710-b0
zyxel ex7501-b0_firmware
zyxel ex7501-b0
zyxel ex5601-t1_firmware
zyxel ex5601-t1
zyxel ex5601-t0_firmware
zyxel ex5601-t0
zyxel ex5512-t0_firmware
zyxel ex5512-t0
zyxel ex5510-b0_firmware
zyxel ex5510-b0
zyxel ex5401-b1_firmware
zyxel ex5401-b1
zyxel ex5401-b0_firmware
zyxel ex5401-b0
zyxel ex3510-b0_firmware
zyxel ex3510-b0
zyxel ex3501-t0_firmware
zyxel ex3501-t0
zyxel ex3500-t0_firmware
zyxel ex3500-t0
zyxel ex3301-t0_firmware
zyxel ex3301-t0
zyxel ex3300-t1_firmware
zyxel ex3300-t1
zyxel ex3300-t0_firmware
zyxel ex3300-t0
zyxel dx5401-b1_firmware
zyxel dx5401-b1
zyxel dx5401-b0_firmware
zyxel dx5401-b0
zyxel dx4510-b0_firmware
zyxel dx4510-b0
zyxel dx3301-t0_firmware
zyxel dx3301-t0
zyxel dx3300-t1_firmware
zyxel dx3300-t1
zyxel dx3300-t0_firmware
zyxel dx3300-t0
zyxel nr7501_firmware
zyxel nr7501
zyxel nr7303_firmware
zyxel nr7303
zyxel nr7302_firmware
zyxel nr7302
zyxel nr7103_firmware
zyxel nr7103
zyxel nr5307_firmware
zyxel nr5307
zyxel nr5103ev2_firmware
zyxel nr5103ev2
zyxel nr5103_firmware
zyxel nr5103

References

Frequently Asked Questions

What is CVE-2024-5412? +
A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenticated attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device. It has a CVSS v3.1 base score of 7.5 (HIGH).
How severe is CVE-2024-5412? +
CVE-2024-5412 has a CVSS v3.1 score of 7.5 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2024-5412? +
CVE-2024-5412 affects products from zyxel, specifically: ax7501-b0, ax7501-b0_firmware, ax7501-b1, ax7501-b1_firmware, dx3300-t0, dx3300-t0_firmware, dx3300-t1, dx3300-t1_firmware, dx3301-t0, dx3301-t0_firmware, dx4510-b0, dx4510-b0_firmware, dx5401-b0, dx5401-b0_firmware, dx5401-b1, dx5401-b1_firmware, emg3525-t50b, emg3525-t50b_firmware, emg5523-t50b, emg5523-t50b_firmware, emg5723-t50k, emg5723-t50k_firmware, ex3300-t0, ex3300-t0_firmware, ex3300-t1, ex3300-t1_firmware, ex3301-t0, ex3301-t0_firmware, ex3500-t0, ex3500-t0_firmware, ex3501-t0, ex3501-t0_firmware, ex3510-b0, ex3510-b0_firmware, ex5401-b0, ex5401-b0_firmware, ex5401-b1, ex5401-b1_firmware, ex5510-b0, ex5510-b0_firmware, ex5512-t0, ex5512-t0_firmware, ex5601-t0, ex5601-t0_firmware, ex5601-t1, ex5601-t1_firmware, ex7501-b0, ex7501-b0_firmware, ex7710-b0, ex7710-b0_firmware, nebula_fwa505, nebula_fwa505_firmware, nebula_fwa510, nebula_fwa510_firmware, nebula_fwa710, nebula_fwa710_firmware, nebula_lte3301-plus, nebula_lte3301-plus_firmware, nr5103, nr5103_firmware, nr5103ev2, nr5103ev2_firmware, nr5307, nr5307_firmware, nr7103, nr7103_firmware, nr7302, nr7302_firmware, nr7303, nr7303_firmware, nr7501, nr7501_firmware, pm3100-t0, pm3100-t0_firmware, pm5100-t0, pm5100-t0_firmware, pm7300-t0, pm7300-t0_firmware, px3321-t1, px3321-t1_firmware, scr50axe_firmware, scr_50axe, vmg3625-t50b, vmg3625-t50b_firmware, vmg3927-t50k, vmg3927-t50k_firmware, vmg4005-b50a, vmg4005-b50a_firmware, vmg4005-b60a, vmg4005-b60a_firmware, vmg8623-t50b, vmg8623-t50b_firmware, vmg8825-t50k, vmg8825-t50k_firmware, wx3100-t0, wx3100-t0_firmware, wx3401-b0, wx3401-b0_firmware, wx5600-t0, wx5600-t0_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-5412? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-5412 — free, no signup required.