CVE-2026-7503
HIGHcode-projects for Plugin cstecgi.cgi setWiFiMultipleConfig buffer overflow
Title source: cnaDescription
A vulnerability was detected in code-projects for Plugin 4.1.2cu.5137. The impacted element is the function setWiFiMultipleConfig in the library /lib/cste_modules/wireless.so of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument wepkey2 results in buffer overflow. The attack can be launched remotely. The exploit is now public and may be used.
Scores
CVSS v3
8.8
EPSS
0.0004
EPSS Percentile
13.1%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
Details
CWE
CWE-119
CWE-120
Status
published
Products (1)
code-projects/for Plugin
4.1.2cu.5137
Published
Apr 30, 2026
Tracked Since
May 01, 2026