← Vulnerability feed

Vulnerability record · CVE-2020-25014 · published 27 November 2020

CVE-2020-25014: Zyxel zld out-of-bounds write vulnerability

Zyxel · Zld

A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted http packet.

9.8 CVSS 3.1 Critical EPSS 4.4% · top 8.9% CWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score, v2 7.5
4.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted http packet.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-25014 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-11667Zyxel Firewall Web Management Path Traversal Allows File Upload and DownloadA path traversal flaw in the web management interface of multiple Zyxel firewall firmware lines (ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN) lets an…KEVEPSS 2.9%analysed8.1CVE-2025-9133Zyxel zld missing authorization vulnerabilityA missing authorization vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from V4.50 th…EPSS 5.5%8.1CVE-2024-42057Zyxel zld os command injection vulnerabilityA command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware v…EPSS 1.3%7.5CVE-2024-42058Zyxel zld null pointer dereference vulnerabilityA null pointer dereference vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50…EPSS 0.62%7.5CVE-2023-4398Zyxel zld integer overflow vulnerabilityAn integer overflow vulnerability in the source code of the QuickSec IPSec toolkit used in the VPN feature of the Zyxel ATP series firmware versions …EPSS 0.88%7.2CVE-2025-8078Zyxel zld os command injection vulnerabilityA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versio…EPSS 1.4%7.2CVE-2024-7203Zyxel zld os command injection vulnerabilityA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firmware ver…EPSS 1.3%7.2CVE-2024-42059Zyxel zld os command injection vulnerabilityA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX series firmware versio…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2020-25014), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.