Vulnerability Description
A buffer overflow in the Mercury MR816v2 (081C3114 4.8.7 Build 110427 Rel 36550n) occurs when the device accepts and stores excessively long hostnames from LAN hosts without proper length validation. The affected code performs unchecked copies/concatenations into fixed-size buffers. A crafted long hostname can overflow the buffer, cause a crash (DoS) and potentially enabling remote code execution.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mercurycom | Mr816 Firmware | 081c3114_4.8.7 |
| Mercurycom | Mr816 | 2.0 |
Related Weaknesses (CWE)
References
- https://damiri.fr/en/cve/CVE-2025-65288ExploitThird Party Advisory
FAQ
What is CVE-2025-65288?
CVE-2025-65288 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A buffer overflow in the Mercury MR816v2 (081C3114 4.8.7 Build 110427 Rel 36550n) occurs when the device accepts and stores excessively long hostnames from LAN hosts without proper length validation. ...
How severe is CVE-2025-65288?
CVE-2025-65288 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-65288?
Check the references section above for vendor advisories and patch information. Affected products include: Mercurycom Mr816 Firmware, Mercurycom Mr816.