Executive brief
A security vulnerability has been identified in Zyxel VMG4005-B50B modems, which are used to provide high-speed internet connectivity. An attacker on the same local network could exploit this flaw to crash the device's port-mapping functionality, preventing applications from automatically configuring network access. While this causes a temporary disruption to specific network features, the device's primary ability to route general internet traffic remains functional.
Technical details
A classic buffer overflow (CWE-120) exists in the UPnP AddPortMapping() command implementation within Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0. The vulnerability is caused by insufficient input validation when processing UPnP commands. An unauthenticated attacker located on the same local area network (LAN) or wireless network (WLAN) can send a specially crafted request to trigger the overflow. Successful exploitation results in a temporary denial-of-service (DoS) of the UPnP service, though the device continues to process standard network traffic. Zyxel has released firmware version 5.13(ABRL.5.5)C0 to address this issue.
Affected products
- Zyxel VMG4005-B50B through 5.13(ABRL.5.4)C0
Timeline
- 2026-06-01: disclosed: Initial disclosure by Zyxel and NVD publication.
- 2026-06-02: advisory: Zyxel security advisory published.
- 2026-06-02: patched: Firmware version 5.13(ABRL.5.5)C0 released.