CVE-2026-32956 is a heap-based buffer overflow vulnerability affecting Silex Technology's SD-330AC and AMC Manager devices, which could allow arbitrary code execution. The flaw exists in the processing of redirect URLs and can be exploited remotely without authentication or user interaction, making it a critical risk. With a CVSS score of 9.8, the vulnerability carries the highest severity rating and poses complete compromise of system confidentiality, integrity, and availability. While exploit code is not yet documented in public vulnerability databases and the exploit prediction score remains extremely low at 0.00043, the vulnerability is listed as active on security hotlists, indicating ongoing attention from the cybersecurity community. Organizations operating these Silex devices should prioritize patching to mitigate potential remote code execution attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.50CPE matchmatch criteria | cpe:2.3:o:silextechnology:sd-330ac_firmware:*:*:*:*:*:*:*:* | ||
< 5.1.0CPE matchmatch criteria | cpe:2.3:a:silextechnology:amc_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.