CVE-2025-10385HIGH 8.8EPSS p87.7%
CVE-2025-10385CVE-2025-10385
Description
A vulnerability has been found in Mercury KM08-708H GiGA WiFi Wave2 1.1. Affected by this issue is the function sub_450B2C of the file /goform/mcr_setSysAdm. The manipulation of the argument ChgUserId leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Scoring
| CVSS 3.1 | 8.8 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.52% probability of exploitation · percentile 87.7% · 2026-06-19T12:03:05Z |
| Published | 2025-09-14 |
| Last modified | 2026-04-15 |
Underlying weaknesses· 2
References
2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Restriction of Operations within the Bounds of a Memory Buffercwe-119 | 0% | live |
| Weakness | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')cwe-120 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.