← Back to browse · API

CVE-2017-2894

Severity
CRITICAL
CVSS
9.8
EPSS
0.31045
Risk score
50.07
CISA KEV
No
PoC
No
Published
2017-11-07
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2017-12035, GHSA-GM65-9XPQ-9G64
Products
Automattic:Mongoose 6.8
Sources
euvd EUVD-2017-12035

Description

An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause a stack buffer overflow resulting in remote code execution. An attacker needs to send a specially crafted MQTT packet over the network to trigger this vulnerability.

References