CVE-2025-3007
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Mar 31, 2025
Updated: Apr 1, 2025
CWE ID 863
Summary
CVE-2025-3007 is a critical vulnerability affecting Novastar CX40 up to version 2.44.0. The issue lies within the getopt function of the /usr/nova/bin/netconfig file in the NetFilter Utility component. A stack-based buffer overflow occurs due to the manipulation of the arguments cmd, netmask, pipeout, and nettask. This vulnerability has been publicly disclosed, and an exploit is available. Despite early contact from security researchers, the vendor has not responded to the disclosure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Parallels Desktop
Affected Vendors
- Parallels