CVE-2014-7278
Estado: ModificadaMedia (5)—
The login page on the ZyXEL SBG-3300 Security Gateway with firmware 1.00(AADY.4)C0 and earlier allows remote attackers to cause a denial of service (persistent web-interface outage) via JavaScript code within unspecified "welcome message" form data that is improperly handled during use for the loginMsg variable's value, a different vulnerability than CVE-2014-7277.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.48%
- Percentil entre todas las CVEs puntuadas: 84
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-20
Referencias
- http://archives.neohapsis.com/archives/bugtraq/2014-10/0025.html
- http://packetstormsecurity.com/files/128550/ZyXEL-SBG-3300-Security-Gateway-Denial-Of-Service.html
- http://seclists.org/fulldisclosure/2014/Oct/20
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96892
- http://archives.neohapsis.com/archives/bugtraq/2014-10/0025.html
- http://packetstormsecurity.com/files/128550/ZyXEL-SBG-3300-Security-Gateway-Denial-Of-Service.html
- http://seclists.org/fulldisclosure/2014/Oct/20
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96892
JSON original (NVD)
Mostrar
{
"id": "CVE-2014-7278",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-10-04T10:55:03.880",
"references": [
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2014-10/0025.html",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://packetstormsecurity.com/files/128550/ZyXEL-SBG-3300-Security-Gateway-Denial-Of-Service.html",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://seclists.org/fulldisclosure/2014/Oct/20",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/96892",
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2014-10/0025.html",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://packetstormsecurity.com/files/128550/ZyXEL-SBG-3300-Security-Gateway-Denial-Of-Service.html",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/fulldisclosure/2014/Oct/20",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/96892",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The login page on the ZyXEL SBG-3300 Security Gateway with firmware 1.00(AADY.4)C0 and earlier allows remote attackers to cause a denial of service (persistent web-interface outage) via JavaScript code within unspecified \"welcome message\" form data that is improperly handled during use for the loginMsg variable's value, a different vulnerability than CVE-2014-7277."
},
{
"lang": "es",
"value": "La página de inicio de sesión en ZyXEL SBG-3300 Security Gateway con firmware 1.00(AADY.4)C0 y anteriores permite a atacantes remotos causar una denegación de servicio (interrupción persistente de la interfaz web) a través de código JavaScript dentro de datos del formulario del 'mensaje de bienvenida' no especificados que se manejan indebidamente durante el uso para el valor de las variables de loginMsg, una vulnerabilidad diferente al CVE-2014-7277."
}
],
"lastModified": "2026-06-17T00:14:40.913",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:sbg3300-n_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "97E405E0-EE80-47E9-89B4-69CB9CF7D1B2",
"versionEndIncluding": "1.00\\(aady.4\\)c0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:sbg3300-n:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BA61B0AC-69CD-4DC0-9615-D034182EC3FB"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}