Out-of-bounds write in ControlVault3 and ControlVault3 Plus - CVE-2025-25050
Published: August 11, 2025
Vulnerability details
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input in the cv_upgrade_sensor_firmware functionality. A local user can use a specially crafted ControlVault API call, trigger an out-of-bounds write and execute arbitrary code on the target system.
Affected software
ControlVault3 Plus
How to mitigate CVE-2025-25050
ControlVault3 Plus - update to 6.2.26.36