CVE-2025-50464 is a pre-authentication buffer overflow vulnerability in the upload.cgi module of iptime NAS firmware v1.5.04. It stems from the unsafe use of strcpy to copy attacker-controlled data from the HTTP CONTENT_TYPE header into a small, fixed-size stack buffer without bounds checking. Rated 6.5 MEDIUM, this vulnerability has a low attack complexity and could lead to partial loss of confidentiality and integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.5.04CPE matchmatch criteria | cpe:2.3:o:iptime:nas_firmware:1.5.04:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.