Security Advisory

CVE-2025-41732

9.8
CRITICAL

Vulnerability Description

An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.
Published Date December 10, 2025
Official Source NIST NVD Advisory