CVE-2022-2025: Grandstream GSD3710 Stack-based Buffer Overflow
an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param length before use the strcopy instruction. The explotation of this vulnerability may lead an attacker to execute a shell with full access.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-2025?
CVE-2022-2025 is a vulnerability that allows an attacker with knowledge of the user/pass of Grandstream GSD3710 version 1.0.11.13 to overflow the stack and execute a shell with full access.
What is the severity of CVE-2022-2025?
CVE-2022-2025 has a severity rating of 9.8, which is considered critical.
How does CVE-2022-2025 affect Grandstream GSD3710?
CVE-2022-2025 affects Grandstream GSD3710 version 1.0.11.13, allowing an attacker to overflow the stack and execute a shell with full access.
Is CVE-2022-2025 already being exploited?
There is no information available about current exploitation of CVE-2022-2025.
What can I do to mitigate CVE-2022-2025?
To mitigate CVE-2022-2025, it is recommended to update Grandstream GSD3710 to a version that addresses the vulnerability.