CVE-2025-25528
Severity CVSS v4.0:
Pending analysis
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
11/02/2025
Last modified:
07/10/2025
Description
Multiple buffer overflow vulnerabilities in Wavlink WL-WN575A3 RPT75A3.V4300, which are caused by not performing strict length checks on user-controlled data. By successfully exploiting the vulnerabilities, attackers can crash the remote devices or execute arbitrary commands without any authorization verification.
Impact
Base Score 3.x
5.10
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:wavlink:wl-wn575a3_firmware:rpt75a3.v4300:*:*:*:*:*:*:* | ||
| cpe:2.3:h:wavlink:wl-wn575a3:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



