Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54134 | A post-authentication command injection vulnerability in the "DNSServer” parameter of the diagnostic function in the Zyxel VMG8825-T50K firmware version V5.50(ABOM.8.5)C0 and earlier could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device. |
Tue, 13 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zyxel dm4200-b0
Zyxel dm4200-b0 Firmware Zyxel emg5723-t50k Zyxel emg5723-t50k Firmware Zyxel vmg3927-t50k Zyxel vmg3927-t50k Firmware Zyxel vmg4005-b50a Zyxel vmg4005-b50a Firmware Zyxel vmg4005-b60a Zyxel vmg4005-b60a Firmware |
|
| CPEs | cpe:2.3:h:zyxel:dm4200-b0:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:emg5723-t50k:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg3927-t50k:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg4005-b50a:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg4005-b60a:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg8825-t50k:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:dm4200-b0_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:emg5723-t50k_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg3927-t50k_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg4005-b50a_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg4005-b60a_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg8825-t50k_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Zyxel dm4200-b0
Zyxel dm4200-b0 Firmware Zyxel emg5723-t50k Zyxel emg5723-t50k Firmware Zyxel vmg3927-t50k Zyxel vmg3927-t50k Firmware Zyxel vmg4005-b50a Zyxel vmg4005-b50a Firmware Zyxel vmg4005-b60a Zyxel vmg4005-b60a Firmware |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 11 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Mar 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A post-authentication command injection vulnerability in the "DNSServer” parameter of the diagnostic function in the Zyxel VMG8825-T50K firmware version V5.50(ABOM.8.5)C0 and earlier could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
Status: PUBLISHED
Assigner: Zyxel
Published:
Updated: 2026-02-26T19:09:42.793Z
Reserved: 2024-11-15T09:33:43.918Z
Link: CVE-2024-11253
Updated: 2025-03-11T14:04:32.629Z
Status : Analyzed
Published: 2025-03-11T02:15:10.043
Modified: 2026-01-13T16:11:20.030
Link: CVE-2024-11253
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:00:51Z
EUVD