Buffer Overflow Vulnerability in INSTAR 2K+ and 4K FCGI Server
CVE-2025-8760

9.3CRITICAL

Key Information:

Vendor

Instar

Status
Vendor
CVE Published:
13 August 2025

What is CVE-2025-8760?

A buffer overflow vulnerability exists in the fcgi_server component of INSTAR 2K+ and 4K versions 3.11.1 Build 1124. This vulnerability is triggered by improper handling of the Authorization argument during execution of the base64_decode function. Attackers can exploit this flaw remotely, potentially allowing unauthorized access or execution of arbitrary code. Immediate attention and remediation actions are recommended to prevent potential exploits.

Affected Version(s)

2K+ 3.11.1 Build 1124

4K 3.11.1 Build 1124

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Imfeld (modzero AG)
.
CVE-2025-8760 : Buffer Overflow Vulnerability in INSTAR 2K+ and 4K FCGI Server