CVE-2022-2025 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 5.3% (pctl 92)
Patch early
A public exploit exists.
Description
an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param length before use the strcopy instruction. The explotation of this vulnerability may lead an attacker to execute a shell with full access.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 5.33% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-121 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2022-09-23 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| grandstream | gds3710 |
| grandstream | gds3710 firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Grandstream GSD3710 1.0.11.13 - Stack Overflow | 2025-06-05 |
References
→ the Explorer · watch your stack · NVD