Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Beetel Connection Manager Stack-Based Buffer Overflow Vulnerability in NetConfig.ini

Vulnerability

A stack-based buffer overflow vulnerability has been identified in Beetel Connection Manager version PCW_BTLINDV1.0.0B04. The issue arises when the application parses the UserName parameter in the NetConfig.ini configuration file. A specially crafted .ini file with an excessively long UserName value can overwrite the Structured Exception Handler (SEH), potentially leading to arbitrary code execution when the application processes the file.

Impact

Exploitation of this vulnerability allows for arbitrary code execution within the context of the application.

Reproduction

To reproduce this vulnerability, create a NetConfig.ini file with a crafted UserName value that exceeds the buffer limit. The overflow will overwrite the SEH, allowing for arbitrary code execution. This vulnerability can be exploited using a Metasploit module available in the Metasploit Framework.

Added: Jul 31, 2025, 4:07 PM
Updated: Jul 31, 2025, 4:07 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.1
remediation
0.0
relevance
0.3
threat
8.2
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.