CVE-2025-14672
HIGHgmg137 snap7-rs < 1.142.1 - Heap-Based Buffer Overflow in TSnap7MicroClient::opWriteArea
Title source: llmDescription
A flaw has been found in gmg137 snap7-rs up to 1.142.1. This impacts the function TSnap7MicroClient::opWriteArea of the file s7_micro_client.cpp. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
technical-description
https://vuldb.com/?id.336401
Permissions Required, VDB Entry signature
permissions-required
https://vuldb.com/?ctiid.336401
Exploit, Issue Tracking, Vendor Advisory exploit
issue-tracking
https://gitee.com/gmg137/snap7-rs/issues/ID2H8E
Scores
CVSS v3
7.3
EPSS
0.0008
EPSS Percentile
24.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-119
CWE-122
Status
published
Products (1)
gmg137/snap7-rs
< 1.142.1
Published
Dec 14, 2025
Tracked Since
Feb 18, 2026