CVE-2026-32955 is a stack-based buffer overflow vulnerability affecting Silex Technology's SD-330AC and AMC Manager products that arises from improper processing of redirect URLs, potentially enabling arbitrary code execution on affected devices. The vulnerability carries a HIGH severity rating of 8.8 CVSS with a network-based attack vector requiring low complexity and user authentication, resulting in complete compromise of confidentiality, integrity, and availability. Exploitation requires network access and valid credentials but no user interaction, making it moderately accessible to authenticated threat actors. Current indicators suggest the vulnerability is not actively exploited in the wild, with no publicly available exploit code and minimal community attention as evidenced by its absence from the Known Exploited Vulnerabilities catalog and inactive status on security watch lists. The FAUCET risk score of 52.0/100 and extremely low EPSS score indicate this remains a lower-priority threat despite its technical severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.50CPE matchmatch criteria | cpe:2.3:o:silextechnology:sd-330ac_firmware:*:*:*:*:*:*:*:* | ||
< 5.1.0CPE matchmatch criteria | cpe:2.3:a:silextechnology:amc_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.