CVE-2025-30742
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Mar 26, 2025
Updated: Mar 27, 2025
CWE ID 193
Summary
CVE-2025-30742 is a vulnerability affecting the httpd.c component in atophttpd 2.8.0. This issue involves an off-by-one error leading to an out-of-bounds read. A maliciously crafted 1024-character req string, missing the final null character, triggers this behavior. Successful exploitation could result in information disclosure or potentially more severe consequences. It is recommended that users update to a version of atophttpd that addresses this vulnerability to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.