PT-2025-50319 · Unknown · Check Account

·

CVE-2025-41730

·

Published

2025-12-10

·

Updated

2025-12-15

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions versions prior to 2.3
Description An unauthenticated remote attacker can exploit unsafe sscanf calls within the check account() function to write arbitrary data into fixed-size stack buffers, potentially leading to full device compromise. The sscanf function is used to read formatted input from a string, and in this case, it does not properly validate the size of the input, allowing an attacker to write beyond the bounds of the buffer. This can overwrite adjacent memory locations, potentially gaining control of the device.
Recommendations Update to a version prior to 2.3. As a temporary workaround, consider disabling the check account() function until a patch is available.

Fix

Memory Corruption

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-41730

Affected Products

Check Account