Description

A post-authentication command injection vulnerability in the "DNSServer” parameter of the diagnostic function in the Zyxel VMG8825-T50K firmware version V5.50(ABOM.8.5)C0 and earlier could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.

INFO

Published Date :

2025-03-11T01:29:00.993Z

Last Modified :

2026-02-26T19:09:42.793Z

Source :

Zyxel
AFFECTED PRODUCTS

The following products are affected by CVE-2024-11253 vulnerability.

Vendors Products
Zyxel
  • Dm4200-b0
  • Dm4200-b0 Firmware
  • Emg5723-t50k
  • Emg5723-t50k Firmware
  • Vmg3927-t50k
  • Vmg3927-t50k Firmware
  • Vmg4005-b50a
  • Vmg4005-b50a Firmware
  • Vmg4005-b60a
  • Vmg4005-b60a Firmware
  • Vmg8825-t50k
  • Vmg8825-t50k Firmware

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact