CVE-2026-3871
Received Received - Intake
Buffer Overflow in Zyxel VMG4005-B50B Firmware via UPnP

Publication date: 2026-06-02

Last updated on: 2026-06-02

Assigner: Zyxel Corporation

Description
A buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a temporary denial-of-service (DoS) condition affecting the UPnP function of the affected device.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-02
Last Modified
2026-06-02
Generated
2026-06-02
AI Q&A
2026-06-02
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
zyxel vmg4005-b50b to 5.13(ABRL.5.4) (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-120 The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a buffer overflow in the UPnP DeletePortMapping() command found in Zyxel VMG4005-B50B firmware versions up to 5.13(ABRL.5.4)C0. An adjacent attacker can exploit this flaw to cause a temporary denial-of-service (DoS) condition that affects the UPnP functionality of the device.


How can this vulnerability impact me? :

The vulnerability can be exploited by an adjacent attacker to trigger a temporary denial-of-service (DoS) condition on the affected device. This means the UPnP function of the device could become unavailable temporarily, potentially disrupting network services that rely on UPnP.


How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

The provided information does not specify how the buffer overflow vulnerability in the UPnP DeletePortMapping() command affects compliance with common standards and regulations such as GDPR or HIPAA.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, users should install the firmware patches released by Zyxel for the affected devices.

  • For the VMG4005-B50B device, update the firmware to version 5.13(ABRL.5.5)C0 or later.
  • For other affected devices like NR7101, Nebula LTE3301-PLUS, and Nebula NR7101, update to their respective patched firmware versions as specified by Zyxel.

Users should contact Zyxel support, their ISP, or visit the Zyxel Community for assistance with obtaining and applying these updates.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart