CVE-2024-50697

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Jan 24, 2025
Updated: Jan 27, 2025
CWE ID 120

Summary

CVE-2024-50697 is a newly disclosed vulnerability affecting SunGrow WiNet-SV200.001.00.P027 and older versions. The issue lies in the decryption process of MQTT messages, where the code responsible for parsing certain TLV fields lacks adequate bounds checking. Consequently, this flaw can lead to a stack-based buffer overflow, potentially allowing attackers to execute arbitrary code and gain unauthorized access to affected systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share