CVE-2025-44895: Medium severity planet technology wgs-804hpt vulnerability
Published May 21, 2025
·Updated
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ipv4Aclkey parameter in the webaclipv4BasedAceAdd function.
Affected Software
3 affected components
FW WGS-804HPT
All of the following
Planet Wgs-804hpt Firmware=1.305b241111
Planet Wgs-804hpt=2.0
Event History
May 21, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-44895?
CVE-2025-44895 is a critical vulnerability due to the potential exploitation via a stack overflow.
2
How do I fix CVE-2025-44895?
To mitigate CVE-2025-44895, update to the latest firmware version provided by Planet Technology that addresses this stack overflow issue.
3
What is the impact of CVE-2025-44895?
CVE-2025-44895 can lead to remote code execution due to the stack overflow in the web_acl_ipv4BasedAceAdd function.
4
Which software is affected by CVE-2025-44895?
CVE-2025-44895 specifically affects the FW WGS-804HPT device running version v1.305b241111.
5
How does the stack overflow occur in CVE-2025-44895?
The stack overflow in CVE-2025-44895 occurs through improper handling of the ipv4Aclkey parameter in the web_acl_ipv4BasedAceAdd function.