CVE-2026-7503

HIGH

code-projects for Plugin cstecgi.cgi setWiFiMultipleConfig buffer overflow

Title source: cna
STIX 2.1

Description

A vulnerability was detected in code-projects for Plugin 4.1.2cu.5137. The impacted element is the function setWiFiMultipleConfig in the library /lib/cste_modules/wireless.so of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument wepkey2 results in buffer overflow. The attack can be launched remotely. The exploit is now public and may be used.

Scores

CVSS v3 8.8
EPSS 0.0004
EPSS Percentile 13.1%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R

Details

CWE
CWE-119 CWE-120
Status published
Products (1)
code-projects/for Plugin 4.1.2cu.5137
Published Apr 30, 2026
Tracked Since May 01, 2026