CVE-2025-25528

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
11/02/2025
Last modified:
07/10/2025

Description

Multiple buffer overflow vulnerabilities in Wavlink WL-WN575A3 RPT75A3.V4300, which are caused by not performing strict length checks on user-controlled data. By successfully exploiting the vulnerabilities, attackers can crash the remote devices or execute arbitrary commands without any authorization verification.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:wavlink:wl-wn575a3_firmware:rpt75a3.v4300:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wl-wn575a3:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools