216.73.217.22

CVE-2025-8760

· Published 13/08/2025 07:15 · Modified 13/08/2025 17:33

Labels: CVE-2025-8760 2025-08-13CVE-2025-8760CWE-119[email protected]

Essential information

Published
13/08/2025 07:15
Modified
13/08/2025 17:33
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability was identified in INSTAR 2K+ and 4K 3.11.1 Build 1124. This affects the function base64_decode of the component fcgi_server. The manipulation of the argument Authorization leads to buffer overflow. It is possible to initiate the attack remotely.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
instar / instar 2k+ cpe:2.3:a:instar:instar_2k+:3.11.1.1124:*:*:*:*:*:*:*
instar / instar 4k cpe:2.3:a:instar:instar_4k:3.11.1.1124:*:*:*:*:*:*:*

References