← back
CVE-2022-2025criticalCWE-121

Grandstream GSD3710 Stack-based Buffer Overflow

48Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9.8epss 4.3%
from disclosure to weapon986 days
Published on NVDSep 23
1st PoC+986d
exploitation probability
4.3%top 10% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param length before use the strcopy instruction. The explotation of this vulnerability may lead an attacker to execute a shell with full access.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.