CVE-2025-3007

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 31, 2025
Updated: Apr 1, 2025
CWE ID 863

Summary

CVE-2025-3007 is a critical vulnerability affecting Novastar CX40 up to version 2.44.0. The issue lies within the getopt function of the /usr/nova/bin/netconfig file in the NetFilter Utility component. A stack-based buffer overflow occurs due to the manipulation of the arguments cmd, netmask, pipeout, and nettask. This vulnerability has been publicly disclosed, and an exploit is available. Despite early contact from security researchers, the vendor has not responded to the disclosure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Parallels Desktop

Affected Vendors

  • Parallels