CVE-2020-25782

CRITICAL

Accfly 720p Firmware < 4.15.77 - Out-of-Bounds Write

Title source: rule

Description

An issue was discovered on Accfly Wireless Security IR Camera 720P System with software versions v3.10.73 through v4.15.77. There is an unauthenticated stack-based buffer overflow in the function CNetClientManage::ServerIP_Proto_Set during incoming message handling.

Exploits (1)

nomisec WRITEUP 3 stars
by tezeb · poc
https://github.com/tezeb/accfly

Scores

CVSS v3 9.8
EPSS 0.2047
EPSS Percentile 95.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (1)
accfly/720p_firmware 3.10.73 - 4.15.77
Published Jan 28, 2021
Tracked Since Feb 18, 2026