peter bassill · operator
$ cve CVE-2022-2025 JSON

CVE-2022-2025 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 5.3% (pctl 92)

Patch early

A public exploit exists.

Description

an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param length before use the strcopy instruction. The explotation of this vulnerability may lead an attacker to execute a shell with full access.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.33% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-121
On CISA KEVno
Public exploityes
Published2022-09-23
Last modified2026-06-17

Affected (2)

VendorProduct
grandstreamgds3710
grandstreamgds3710 firmware

Public exploits

SourceTitleDate
exploit-dbGrandstream GSD3710 1.0.11.13 - Stack Overflow2025-06-05

References

→ the Explorer  ·  watch your stack  ·  NVD