CVE-2025-63701 is a heap corruption vulnerability in the Advantech TP-3250 printer driver (DrvUI_x64_ADVANTECH.dll v0.3.9200.20789) that affects Advantech TP-3250 products and firmware. It occurs when the DocumentPropertiesW() function is called with an undersized output buffer, leading to invalid memory operations. This vulnerability has a CVSS score of 6.8 (Medium) and requires local access, potentially causing denial of service through application crashes and possible user-space code execution. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.3.9200.20789CPE matchmatch criteria | cpe:2.3:o:advantech:tp_3250_firmware:0.3.9200.20789:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.