CVE-2025-65288

A buffer overflow in the Mercury MR816v2 (081C3114 4.8.7 Build 110427 Rel 36550n) occurs when the device accepts and stores excessively long hostnames from LAN hosts without proper length validation. The affected code performs unchecked copies/concatenations into fixed-size buffers. A crafted long hostname can overflow the buffer, cause a crash (DoS) and potentially enabling remote code execution.
References
Link Resource
https://damiri.fr/en/cve/CVE-2025-65288 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:mercurycom:mr816_firmware:081c3114_4.8.7:build_110427:*:*:*:*:*:*
cpe:2.3:h:mercurycom:mr816:2.0:*:*:*:*:*:*:*

History

12 Dec 2025, 14:32

Type Values Removed Values Added
First Time Mercurycom mr816
Mercurycom mr816 Firmware
Mercurycom
References () https://damiri.fr/en/cve/CVE-2025-65288 - () https://damiri.fr/en/cve/CVE-2025-65288 - Exploit, Third Party Advisory
CPE cpe:2.3:o:mercurycom:mr816_firmware:081c3114_4.8.7:build_110427:*:*:*:*:*:*
cpe:2.3:h:mercurycom:mr816:2.0:*:*:*:*:*:*:*

10 Dec 2025, 21:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-120

09 Dec 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-09 17:15

Updated : 2025-12-12 14:32


NVD link : CVE-2025-65288

Mitre link : CVE-2025-65288

CVE.ORG link : CVE-2025-65288


JSON object : View

Products Affected

mercurycom

  • mr816_firmware
  • mr816
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')