CVE-2026-7287
Received Received - Intake
Buffer Overflow in Zyxel NWA1100-N Firmware

Publication date: 2026-05-12

Last updated on: 2026-05-12

Assigner: Zyxel Corporation

Description
** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), formUpgradeCert(), and formDelcert() functions of the β€œwebs” binary in Zyxel NWA1100-N customized firmware version 1.00(AACE.1)C0 could allow an attacker to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request to a vulnerable device.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-12
Last Modified
2026-05-12
Generated
2026-06-01
AI Q&A
2026-05-12
EPSS Evaluated
2026-05-31
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
zyxel nwa1100-n 1.00(aace.1)c0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-120 The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a buffer overflow in several functions (formWep(), formWlAc(), formPasswordSetup(), formUpgradeCert(), and formDelcert()) of the "webs" binary in Zyxel NWA1100-N customized firmware version 1.00(AACE.1)C0.

An attacker can exploit this by sending a specially crafted HTTP request to the vulnerable device.

The result of this exploitation could be a denial-of-service (DoS) condition, meaning the device could become unavailable or stop functioning properly.


How can this vulnerability impact me? :

The primary impact of this vulnerability is that an attacker can cause a denial-of-service (DoS) condition on the affected Zyxel NWA1100-N device.

This means the device could become unresponsive or stop working, potentially disrupting network connectivity or services relying on this device.


What immediate steps should I take to mitigate this vulnerability?

The vulnerability affects Zyxel NWA1100-N customized firmware version 1.00(AACE.1)C0 and allows denial-of-service (DoS) via crafted HTTP requests.

Since no specific mitigation steps or patches are mentioned in the provided resources, the best immediate action is to consider upgrading to a newer supported product or firmware version, as Zyxel advises migrating to newer solutions before end-of-life stages.

Additionally, restricting or monitoring HTTP traffic to the vulnerable device to detect or block suspicious crafted requests may help reduce exposure.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart