CVE-2025-15247 is a critical heap-based buffer overflow vulnerability affecting the gmg137 snap7-rs library, specifically within the snap7_rs::client::S7Client::download function. This flaw allows for remote code execution with a CVSS score of 9.8, indicating a severe impact on confidentiality, integrity, and availability. While the exploit is publicly available, there is no evidence of active exploitation, and community discussion and media coverage are currently minimal. The project maintainers have been notified but have not yet responded or provided a fix for this rolling release product.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:gmg137:snap7-rs:-:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.