CVE-2025-30742

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Mar 26, 2025
Updated: Mar 27, 2025
CWE ID 193

Summary

CVE-2025-30742 is a vulnerability affecting the httpd.c component in atophttpd 2.8.0. This issue involves an off-by-one error leading to an out-of-bounds read. A maliciously crafted 1024-character req string, missing the final null character, triggers this behavior. Successful exploitation could result in information disclosure or potentially more severe consequences. It is recommended that users update to a version of atophttpd that addresses this vulnerability to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share