# N/A
## 概述
Zyxel DX3301-T0 固件版本 5.50(ABVY.6.3)C0 及更早版本中存在资源消耗漏洞,可用于发起 Slowloris 风格的拒绝服务(DoS)攻击。
## 影响版本
- 固件版本:5.50(ABVY.6.3)C0 及此前版本
## 细节
该漏洞存在于设备的 Web 服务器组件中,攻击者可通过构造 Slowloris 类型的 HTTP 请求,持续维持大量半开连接,导致服务器资源耗尽。
## 影响
- 合法的 HTTP 请求可能被临时阻塞
- Web 管理界面的部分访问功能可能受到干扰
- 其他网络服务不受影响
是否为 Web 类漏洞: 未知
判断理由:
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
标题: Security Advisories | Zyxel Networks -- 🔗来源链接
标签:vendor-advisory
神龙速读:
- 漏洞关键信息:
- **CVE ID** | **Title** | **Last Updated**
- CVE-2025-6599, CVE-2025-8693 | Zyxel security advisory for uncontrolled resource consumption and command injection vulnerabilities in certain 4G LTE/5G NR CPE, DSL/Ethernet CPE, Fiber ONTs, Security Routers, and Wireless Extenders | November 18, 2025
- CVE-2025-8078, CVE-2025-9133 | Zyxel security advisory for post-authentication command injection and missing authorization vulnerabilities in ZLD firewalls | October 21, 2025
- CVE-2025-7673 | Zyxel security advisory for remote code execution and denial-of-service vulnerabilities of CPE | July 16, 2025
- CVE-2025-6265 | Zyxel security advisory for path traversal vulnerability in APs | July 15, 2025
- CVE-2025-1731, CVE-2025-1732 | Zyxel security advisory for incorrect permission assignment and improper privilege management vulnerabilities in USG FLEX H series firewalls | April 22, 2025
- CVE-2024-11253, CVE-2024-12009, CVE-2024-12010 | Zyxel security advisory for post-authentication command injection vulnerabilities in certain DSL/Ethernet CPE, fiber ONT, and WiFi extender devices | March 11, 2025
- CVE-2024-40890, CVE-2024-40891, CVE-2025-0890 | Zyxel security advisory for command injection and insecure default credentials vulnerabilities in certain legacy DSL CPE | February 4, 2025
- CVE-2024-12398 | Zyxel security advisory for improper privilege management vulnerability in APs and security router devices | January 14, 2025
- CVE-2024-8748, CVE-2024-9197, CVE-2024-9200 | Zyxel security advisory for buffer overflow and post-authentication command injection vulnerabilities in some 4G LTE/5G NR CPE, DSL/Ethernet CPE, fiber ONTs, and WiFi extenders | December 3, 2024
- CVE-2024-11667 | Zyxel security advisory: protecting against recent firewall threats | November 27, 2024
暂无评论