CVE-2025-14673
HIGHgmg137 snap7-rs < 1.142.1 - Heap-Based Buffer Overflow in S7Client::as_ct_write
Title source: llmDescription
A vulnerability has been found in gmg137 snap7-rs up to 1.142.1. Affected is the function snap7_rs::client::S7Client::as_ct_write of the file /tests/snap7-rs/src/client.rs. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
technical-description
https://vuldb.com/?id.336402
Permissions Required, VDB Entry signature
permissions-required
https://vuldb.com/?ctiid.336402
Exploit, Issue Tracking, Vendor Advisory exploit
issue-tracking
https://gitee.com/gmg137/snap7-rs/issues/ID2H74
Scores
CVSS v3
7.3
EPSS
0.0008
EPSS Percentile
24.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-119
CWE-122
Status
published
Products (1)
gmg137/snap7-rs
< 1.142.1
Published
Dec 14, 2025
Tracked Since
Feb 18, 2026