CVE-2026-32964 is a CRLF injection vulnerability affecting Silex Technology's SD-330AC and AMC Manager products that allows attackers to inject arbitrary entries into system configuration files by processing specially crafted configuration data. This improper neutralization of carriage return/line feed sequences could enable unauthorized modification of system settings and behavior. The vulnerability carries a CVSS 3.1 score of 6.5 (Medium severity) with a network-based attack vector requiring no authentication or user interaction, making it relatively accessible. However, the impact is limited to integrity and availability concerns with no confidentiality impact, and the attack complexity is low. The FAUCET Risk Score of 35 out of 100 indicates moderate organizational risk. There is currently no evidence of active exploitation, with the vulnerability absent from the Known Exploited Vulnerabilities catalog and showing minimal community attention reflected in the very low EPSS score of 0.0004. No public exploit code is available, and the vulnerability remains on an inactive hot list, suggesting it has not yet become a widespread threat in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.50CPE matchmatch criteria | cpe:2.3:o:silextechnology:sd-330ac_firmware:*:*:*:*:*:*:*:* | ||
< 5.1.0CPE matchmatch criteria | cpe:2.3:a:silextechnology:amc_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.