CVE-2025-15247

A vulnerability was identified in gmg137 snap7-rs up to 153d3e8c16decd7271e2a5b2e3da4d6f68589424. Affected by this issue is the function snap7_rs::client::S7Client::download of the file client.rs. Such manipulation leads to heap-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.
References
Link Resource
https://gitee.com/gmg137/snap7-rs/issues/ID2H7V Issue Tracking
https://vuldb.com/?ctiid.338637 Permissions Required VDB Entry
https://vuldb.com/?id.338637 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:gmg137:snap7-rs:-:*:*:*:*:*:*:*

History

12 Jan 2026, 14:22

Type Values Removed Values Added
References () https://gitee.com/gmg137/snap7-rs/issues/ID2H7V - () https://gitee.com/gmg137/snap7-rs/issues/ID2H7V - Issue Tracking
References () https://vuldb.com/?ctiid.338637 - () https://vuldb.com/?ctiid.338637 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.338637 - () https://vuldb.com/?id.338637 - Third Party Advisory, VDB Entry
CPE cpe:2.3:a:gmg137:snap7-rs:-:*:*:*:*:*:*:*
First Time Gmg137
Gmg137 snap7-rs

30 Dec 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-30 12:15

Updated : 2026-01-12 14:22


NVD link : CVE-2025-15247

Mitre link : CVE-2025-15247

CVE.ORG link : CVE-2025-15247


JSON object : View

Products Affected

gmg137

  • snap7-rs
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-122

Heap-based Buffer Overflow