CVE-2025-34127
Severity CVSS v4.0:
CRITICAL
Type:
CWE-94
Code Injection
Publication date:
16/07/2025
Last modified:
17/07/2025
Description
A stack-based buffer overflow exists in Achat v0.150 in its default configuration. By sending a specially crafted message to the UDP port 9256, an attacker can overwrite the structured exception handler (SEH) due to insufficient bounds checking on user-supplied input leading to remote code execution.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL



