CVE-2026-3871
Deferred Deferred - Pending Action
Buffer Overflow in Zyxel VMG4005-B50B Firmware via UPnP

Publication date: 2026-06-02

Last updated on: 2026-06-02

Assigner: Zyxel Corporation

Description
A buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a temporary denial-of-service (DoS) condition affecting the UPnP function of the affected device.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-02
Last Modified
2026-06-02
Generated
2026-06-22
AI Q&A
2026-06-02
EPSS Evaluated
2026-06-21
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
zyxel vmg4005-b50b to 5.13(ABRL.5.4) (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-120 The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a buffer overflow in the UPnP DeletePortMapping() command found in Zyxel VMG4005-B50B firmware versions up to 5.13(ABRL.5.4)C0. An adjacent attacker can exploit this flaw to cause a temporary denial-of-service (DoS) condition that affects the UPnP functionality of the device.

Impact Analysis

The vulnerability can be exploited by an adjacent attacker to trigger a temporary denial-of-service (DoS) condition on the affected device. This means the UPnP function of the device could become unavailable temporarily, potentially disrupting network services that rely on UPnP.

Compliance Impact

The provided information does not specify how the buffer overflow vulnerability in the UPnP DeletePortMapping() command affects compliance with common standards and regulations such as GDPR or HIPAA.

Mitigation Strategies

To mitigate this vulnerability, users should install the firmware patches released by Zyxel for the affected devices.

  • For the VMG4005-B50B device, update the firmware to version 5.13(ABRL.5.5)C0 or later.
  • For other affected devices like NR7101, Nebula LTE3301-PLUS, and Nebula NR7101, update to their respective patched firmware versions as specified by Zyxel.

Users should contact Zyxel support, their ISP, or visit the Zyxel Community for assistance with obtaining and applying these updates.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-3871. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart