Home
CRITICAL: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
V0.0 (semver) before V1.49
affected
Default status
unaffected
V0.0 (semver) before V1.62
affected
Default status
unaffected
V0.0 (semver) before V1.62
affected
Description
An unauthenticated remote attacker may use a stack based buffer overflow in the u-link Management API to gain full access on the affected devices.
Problem types
CWE-121 Stack-based Buffer Overflow
Product status
V0.0 (semver) before V1.49
V0.0 (semver) before V1.62
V0.0 (semver) before V1.62
Credits
Reid Wightman of Dragos Inc.
References
certvde.com/de/advisories/VDE-2025-052