Stack-Based Buffer Overflow Vulnerability in SunGrow WiNet-SV200
CVE-2024-50695

9.8CRITICAL

Key Information:

Vendor

SunGrow

Vendor
CVE Published:
24 January 2025

What is CVE-2024-50695?

The SunGrow WiNet-SV200 versions up to 0.001.00.P027 are susceptible to a stack-based buffer overflow when handling MQTT messages. This vulnerability arises from inadequate boundary checks for MQTT topic strings, potentially allowing an attacker to exploit the flaw by crafting malicious MQTT messages. Successful exploitation could compromise system integrity, leading to unauthorized access or execution of arbitrary code.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.