Stack-Based Buffer Overflow Vulnerability in u-link Management API by Vendor
CVE-2025-41687

9.8CRITICAL

What is CVE-2025-41687?

An unauthenticated remote attacker can exploit a stack-based buffer overflow in the u-link Management API, potentially allowing arbitrary command execution and full access to the affected devices. This vulnerability poses a significant risk as it does not require user authentication, making it easier for malicious actors to compromise systems without any prior access.

Affected Version(s)

IE-SR-2TX-WL V0.0

IE-SR-2TX-WL-4G-EU V0.0

IE-SR-2TX-WL-4G-US-V V0.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Reid Wightman of Dragos Inc.
.
CVE-2025-41687 : Stack-Based Buffer Overflow Vulnerability in u-link Management API by Vendor