CVE-2025-7208 is a critical heap-based buffer overflow vulnerability affecting the edump function within the /src/plan9port/src/libsec/port/x509.c library of 9fans plan9port. This flaw allows for remote code execution or denial of service due to improper handling of memory. With a CVSS score of 9.8 (CRITICAL), this vulnerability is easily exploitable over the network without requiring user interaction or privileges, leading to high impacts on confidentiality, integrity, and availability. While the exploit has been publicly disclosed, there is currently no evidence of active exploitation, nor are there readily available Metasploit, Nuclei, or ExploitDB modules. Community discussion and media coverage are minimal, suggesting low public awareness despite the disclosed exploit.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2025-03-29CPE matchmatch criteria | cpe:2.3:a:9fans:plan9port:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.