CVE 9.3 CRITICAL

INSTAR 2K+/4K fcgi_server base64_decode buffer overflow_CVE-2025-8760

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X

Description

A vulnerability was identified in INSTAR 2K+ and 4K 3.11.1 Build 1124. This affects the function base64_decode of the component fcgi_server. The manipulation of the argument Authorization leads to buffer overflow. It is possible to initiate the attack remotely.

Basic Information

ID CVE-2025-8760
Source VulDB
Published Aug 13, 2025 at 06:14

Affected Product

Vendor INSTAR
Product 2K+
Version 3.11.1 Build 1124
Affected Versions INSTAR 2K+ 3.11.1 Build 1124
INSTAR 4K 3.11.1 Build 1124

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.