CVE-2026-3823 is a critical Stack-based Buffer Overflow vulnerability affecting Atop Technologies EHG2408 series switches, including specific firmware versions. This flaw allows unauthenticated remote attackers to control program execution flow and execute arbitrary code. With a CVSS score of 9.8, it poses a severe risk due to its network attack vector, low attack complexity, and complete impact on confidentiality, integrity, and availability. There is no user interaction or privileges required for exploitation. Currently, there is no evidence of active exploitation, nor is public exploit code available, and community discussion or media coverage remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.36CPE matchmatch criteria | cpe:2.3:o:blackbeartechhive:atop_ehg2408_firmware:*:*:*:*:*:*:*:* | ||
< 3.36CPE matchmatch criteria | cpe:2.3:o:blackbeartechhive:atop_ehg2408-2sfp_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.