CVE-2025-25527

MEDIUM

Ruijie Rg-nbr2600s Firmware - Buffer Overflow

Title source: rule
STIX 2.1

Description

Buffer overflow vulnerability in Ruijie RG-NBR2600S Gateway 10.3(4b12) due to the lack of length verification, which is related to the configuration of source address NAT rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.

References (1)

Core 1

Scores

CVSS v3 5.1
EPSS 0.0009
EPSS Percentile 24.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-120
Status published
Products (1)
ruijie/rg-nbr2600s_firmware 10.3\(4b12\)
Published Feb 11, 2025
Tracked Since Feb 18, 2026