CVE-2025-6599

HIGH WAF: Medium
CVSS 7.5 Published: 2025-11-18
CWE-400

An uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an attacker to perform Slowloris‑style denial‑of‑service (DoS) attacks. Such attacks may temporarily block legitimate HTTP requests and partially disrupt access to the web management interface, while other networking services remain unaffected.

WAF Coverage Analysis

Uncontrolled Resource Consumption Medium WAF Coverage

OWASP: A05:2021 Security Misconfiguration

912xxx - DOS Protection

Affected Software

VendorProductVersion
zyxellte3301-plus_firmwareup to 1.00\(abqu.7\)c0
zyxelnr5103_firmwareup to 4.19\(abyc.8\)c0
zyxelnr5103e_firmwareup to 1.00\(acdj.1\)c0
zyxelnr5309_firmwareup to 1.00\(ackp.1\)b3
zyxelnr7302_firmwareup to 5.00\(acha.5\)c0
zyxelnr7303_firmwareup to 1.00\(acei.1\)c0
zyxelnebula_fwa505_firmwareup to 1.19\(acko.0\)c0
zyxelnebula_fwa510_firmwareup to 1.20\(acgd.1\)c0
zyxelnebula_fwa515_firmwareup to 1.50\(acpz.0\)c0
zyxelnebula_fwa710_firmwareup to 1.20\(acgc.0\)c0

References

Back to CVE Database