PT-2025-50320 · Unknown · Check Cookie
Daniel Hulliger
·
Published
2025-12-10
·
Updated
2025-12-15
·
CVE-2025-41732
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
versions prior to 2025-41732
Description
An unauthenticated remote attacker can exploit unsafe
sscanf calls within the check cookie() function to write arbitrary data into fixed-size stack buffers, potentially leading to full device compromise. The sscanf() function is used to read formatted input from a string, and in this case, it does not properly validate the size of the input, allowing an attacker to write beyond the bounds of the buffer. This can overwrite adjacent memory locations, potentially overwriting critical data or code, and ultimately gaining control of the device.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Memory Corruption
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Check Cookie