PT-2025-50320 · Unknown · Check Cookie

Daniel Hulliger

·

Published

2025-12-10

·

Updated

2025-12-15

·

CVE-2025-41732

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions versions prior to 2025-41732
Description An unauthenticated remote attacker can exploit unsafe sscanf calls within the check cookie() function to write arbitrary data into fixed-size stack buffers, potentially leading to full device compromise. The sscanf() function is used to read formatted input from a string, and in this case, it does not properly validate the size of the input, allowing an attacker to write beyond the bounds of the buffer. This can overwrite adjacent memory locations, potentially overwriting critical data or code, and ultimately gaining control of the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-41732

Affected Products

Check Cookie