CRITICAL🇵🇱 Wersja polska

CVE-2026-32956

CVSS 9.3v4.0pub. 2026-04-20upd. 2026-04-22

SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in processing the redirect URLs. Arbitrary code may be executed on the device.

🤖 AI Analysis
How it works

The vulnerability (CWE-122) involves a buffer overflow in the heap area during processing of input data containing redirect URLs. An attacker can supply a specially crafted URL that exceeds the intended buffer size, overwriting adjacent memory areas. This allows injection and execution of arbitrary code in the context of the process handling redirects.

Impact

An attacker can gain full control over the device by executing arbitrary code remotely without requiring authentication. This results in loss of confidentiality, integrity, and availability of device resources.

Mitigation & patch

Apply patches available from the manufacturer according to the references (https://www.silex.jp/support/security-advisories/en/2026-001). Until updating, it is recommended to restrict network access to SD-330AC devices and the AMC Manager system only to trusted hosts, for example through firewall rules or network segmentation.

Who is affected

Silex Technology SD-330AC (firmware) and Silex Technology AMC Manager — versions indicated in the manufacturer's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Silextechnology Amc Manager

    APP
    Silextechnology
    < 5.1.0
  • Silextechnology Sd 330ac

    HW
    Silextechnology
    all versions
  • Silextechnology Sd 330ac Firmware

    OS
    Silextechnology
    < 1.50
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2026-32955HIGH8.7same product

SD-330AC and AMC Manager provided by silex technology, Inc. contain a stack-based buffer overflow vulnerabilit...

CVE-2026-32959HIGH8.2same product

SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a use of a broken or risky c...

CVE-2026-32960HIGH7.1same product

SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a sensitive information in r...

CVE-2026-32965HIGH8.7same product

Initialization of a resource with an insecure default vulnerability exists in SD-330AC and AMC Manager provide...

CVE-2026-32964MEDIUM6.9same product

Urządzenia SD-330AC i AMC Manager dostarczone przez silex technology, Inc. zawierają podatność związaną z niep...