CVE-2025-34127

Severity CVSS v4.0:
CRITICAL
Type:
CWE-94 Code Injection
Publication date:
16/07/2025
Last modified:
17/07/2025

Description

A stack-based buffer overflow exists in Achat v0.150 in its default configuration. By sending a specially crafted message to the UDP port 9256, an attacker can overwrite the structured exception handler (SEH) due to insufficient bounds checking on user-supplied input leading to remote code execution.