CVE-2026-3871
Buffer Overflow in Zyxel VMG4005-B50B Firmware via UPnP
Publication date: 2026-06-02
Last updated on: 2026-06-02
Assigner: Zyxel Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| zyxel | vmg4005-b50b | to 5.13(ABRL.5.4) (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-120 | The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a buffer overflow in the UPnP DeletePortMapping() command found in Zyxel VMG4005-B50B firmware versions up to 5.13(ABRL.5.4)C0. An adjacent attacker can exploit this flaw to cause a temporary denial-of-service (DoS) condition that affects the UPnP functionality of the device.
How can this vulnerability impact me? :
The vulnerability can be exploited by an adjacent attacker to trigger a temporary denial-of-service (DoS) condition on the affected device. This means the UPnP function of the device could become unavailable temporarily, potentially disrupting network services that rely on UPnP.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
The provided information does not specify how the buffer overflow vulnerability in the UPnP DeletePortMapping() command affects compliance with common standards and regulations such as GDPR or HIPAA.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, users should install the firmware patches released by Zyxel for the affected devices.
- For the VMG4005-B50B device, update the firmware to version 5.13(ABRL.5.5)C0 or later.
- For other affected devices like NR7101, Nebula LTE3301-PLUS, and Nebula NR7101, update to their respective patched firmware versions as specified by Zyxel.
Users should contact Zyxel support, their ISP, or visit the Zyxel Community for assistance with obtaining and applying these updates.