Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-6599

24
FAUCET Score

CVE-2025-6599 is an uncontrolled resource consumption vulnerability affecting Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C0 and earlier. An unauthenticated attacker can exploit this flaw remotely to launch Slowloris-style denial-of-service (DoS) attacks against the device's web server. This can temporarily block legitimate HTTP requests and disrupt access to the web management interface, though other networking services remain unaffected. The vulnerability has a CVSS score of 7.5 HIGH, indicating a significant impact on availability with low attack complexity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.00\(abqu.7\)c0CPE matchmatch criteria
cpe:2.3:o:zyxel:lte3301-plus_firmware:*:*:*:*:*:*:*:*
<= 4.19\(abyc.8\)c0CPE matchmatch criteria
cpe:2.3:o:zyxel:nr5103_firmware:*:*:*:*:*:*:*:*
<= 1.00\(acdj.1\)c0CPE matchmatch criteria
cpe:2.3:o:zyxel:nr5103e_firmware:*:*:*:*:*:*:*:*
<= 1.00\(ackp.1\)b3CPE matchmatch criteria
cpe:2.3:o:zyxel:nr5309_firmware:*:*:*:*:*:*:*:*
<= 5.00\(acha.5\)c0CPE matchmatch criteria
cpe:2.3:o:zyxel:nr7302_firmware:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
22.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0031 is in the 5th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

zyxelpatch availablevia llm_extracted
View patch
dockervendor investigatingvia llm_extracted
View patch

Vendor Advisories (2)

dockerllm-docker-ada9965157dadf0b

Zyxel security advisory for uncontrolled resource consumption and command injection vulnerabilities in certain 4G LTE/5G NR CPE, DSL/Ethernet CPE, Fiber ONTs, Security Routers, and Wireless Extenders

Nov 18, 2025
zyxelllm-zyxel-7deec0056f533f19

Zyxel security advisory for uncontrolled resource consumption and command injection vulnerabilities in certain 4G LTE/5G NR CPE, DSL/Ethernet CPE, Fiber ONTs, Security Routers, and Wireless Extenders

Nov 18, 2025

References

zyxel.com / global/en/support/security-advisories/zyxel-security-advisory-for-uncontrolled-resource-consumption-and-command-injection-vulnerabilities-in-certain-4g-lte-5g-nr-cpe-dsl-ethernet-cpe-fiber-onts-security-routers-and-wireless-extenders-11-18-2025
Vendor Advisory