CVE-2017-7185 is a high-severity use-after-free vulnerability affecting Cesanta Mongoose Embedded Web Server Library versions 6.7 and earlier, and Mongoose OS versions 1.2 and earlier. A remote attacker can exploit this by sending a malformed multipart/form-data POST request without a MIME boundary, leading to a denial of service (crash). The attack is network-based, low complexity, and requires no user interaction or privileges. While not on the KEV catalog, an exploit (EDB-41826) exists, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.7CPE matchmatch criteria | cpe:2.3:a:cesanta:mongoose_embedded_web_server_library:*:*:*:*:*:*:*:* | ||
<= 1.2CPE matchmatch criteria | cpe:2.3:o:cesanta:mongoose_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.