24h | 7d | 30d

Overview

  • UTT
  • 进取 520W

11 Jan 2026
Published
12 Jan 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.04%

KEV

Description

A vulnerability was identified in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formFireWall. Such manipulation of the argument GroupName leads to buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 1 hour ago

Overview

  • UTT
  • 进取 520W

11 Jan 2026
Published
11 Jan 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.04%

KEV

Description

A vulnerability was determined in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/formConfigFastDirectionW. This manipulation of the argument ssid causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 1 hour ago

Overview

  • nasa
  • CryptoLib

10 Jan 2026
Published
10 Jan 2026
Updated

CVSS v4.0
MEDIUM (6.3)
EPSS
0.04%

KEV

Description

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, when the KMC server returns a non-200 HTTP status code, cryptography_encrypt() and cryptography_decrypt() return immediately without freeing previously allocated buffers. Each failed request leaks approximately 467 bytes. Repeated failures (from a malicious server or network issues) can gradually exhaust memory. This issue has been patched in version 1.4.3.

Statistics

  • 1 Post
  • 5 Interactions

Last activity: 1 hour ago

Overview

  • nasa
  • CryptoLib

10 Jan 2026
Published
10 Jan 2026
Updated

CVSS v4.0
HIGH (8.2)
EPSS
0.05%

KEV

Description

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, an out-of-bounds heap read vulnerability in cryptography_encrypt() occurs when parsing JSON metadata from KMC server responses. The flawed strtok iteration pattern uses ptr + strlen(ptr) + 1 which reads one byte past allocated buffer boundaries when processing short or malformed metadata strings. This issue has been patched in version 1.4.3.

Statistics

  • 1 Post
  • 5 Interactions

Last activity: 1 hour ago

Overview

  • nasa
  • CryptoLib

10 Jan 2026
Published
10 Jan 2026
Updated

CVSS v3.1
HIGH (8.2)
EPSS
0.05%

KEV

Description

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the Crypto_AOS_ProcessSecurity function reads memory without valid bounds checking when parsing AOS frame hashes. This issue has been patched in version 1.4.3.

Statistics

  • 1 Post
  • 5 Interactions

Last activity: 1 hour ago

Overview

  • nasa
  • CryptoLib

10 Jan 2026
Published
10 Jan 2026
Updated

CVSS v4.0
HIGH (8.2)
EPSS
0.04%

KEV

Description

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, there is an out-of-bounds heap read vulnerability in cryptography_aead_encrypt(). This issue has been patched in version 1.4.3.

Statistics

  • 1 Post
  • 5 Interactions

Last activity: 1 hour ago

Overview

  • nasa
  • CryptoLib

10 Jan 2026
Published
10 Jan 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.07%

KEV

Description

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, CryptoLib’s KMC crypto service integration is vulnerable to a heap buffer overflow when decoding Base64-encoded ciphertext/cleartext fields returned by the KMC service. The decode destination buffer is sized using an expected output length (len_data_out), but the Base64 decoder writes output based on the actual Base64 input length and does not enforce any destination size limit. An oversized Base64 string in the KMC JSON response can cause out-of-bounds writes on the heap, resulting in process crash and potentially code execution under certain conditions. This issue has been patched in version 1.4.3.

Statistics

  • 1 Post
  • 5 Interactions

Last activity: 1 hour ago

Overview

  • nasa
  • CryptoLib

10 Jan 2026
Published
10 Jan 2026
Updated

CVSS v3.1
HIGH (7.3)
EPSS
0.04%

KEV

Description

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the Crypto_Config_Add_Gvcid_Managed_Parameters function only checks whether gvcid_counter > GVCID_MAN_PARAM_SIZE. As a result, it allows up to the 251st entry, which causes a write past the end of the array, overwriting gvcid_counter located immediately after gvcid_managed_parameters_array[250]. This leads to an out-of-bounds write, and the overwritten gvcid_counter may become an arbitrary value, potentially affecting the parameter lookup/registration logic that relies on it. This issue has been patched in version 1.4.3.

Statistics

  • 1 Post
  • 5 Interactions

Last activity: 1 hour ago

Overview

  • nasa
  • CryptoLib

10 Jan 2026
Published
10 Jan 2026
Updated

CVSS v4.0
MEDIUM (6.3)
EPSS
0.05%

KEV

Description

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the cryptography_encrypt() function allocates multiple buffers for HTTP requests and JSON parsing that are never freed on any code path. Each call leaks approximately 400 bytes of memory. Sustained traffic can gradually exhaust available memory. This issue has been patched in version 1.4.3.

Statistics

  • 1 Post
  • 5 Interactions

Last activity: 1 hour ago

Overview

  • nasa
  • CryptoLib

10 Jan 2026
Published
10 Jan 2026
Updated

CVSS v4.0
HIGH (8.2)
EPSS
0.04%

KEV

Description

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the libcurl write_callback function in the KMC crypto service client allows unbounded memory growth by reallocating response buffers without any size limit or overflow check. A malicious KMC server can return arbitrarily large HTTP responses, forcing the client to allocate excessive memory until the process is terminated by the OS. This issue has been patched in version 1.4.3.

Statistics

  • 1 Post
  • 5 Interactions

Last activity: 1 hour ago
Showing 31 to 40 of 42 CVEs