Impact
A remote, unauthenticated client can exploit the rigctld send_raw command on TCP port 4532 to trigger two distinct issues in Hamlib versions prior to 4.7.2. The first flaw is a stack out‑of‑bounds write that places a NUL byte beyond a 200‑byte buffer, which can corrupt adjacent stack memory or crash the daemon. The second flaw is an oversized copy that returns up to 198 bytes of uninitialized stack data to the client. These weaknesses correspond to CWE‑787 and CWE‑908 and allow a remote attacker to cause denial of service or exfiltrate sensitive data from the stack. The impact is limited to the daemon process and any applications that rely on the library for radio control.
Affected Systems
Hamlib, the ham radio control library used by radios, rotators, and amplifiers, is affected. Any installation running a version older than 4.7.2 is vulnerable. Although the version field was not explicitly listed in the CNA data, the advisory states that all releases prior to 4.7.2 contain the flaw.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity. The EPSS score of less than 1% suggests a low probability of exploitation at the moment, and the vulnerability is not currently recorded in the CISA KEV catalog. The likely attack vector is an unauthenticated TCP connection to port 4532 made by a remote client, after which a short payload is sent that triggers both the out‑of‑bounds write and the uninitialized data copy. Exploitability requires remote network access, but no privileged credentials are needed. The consequence range is from a simple crash to potential data leakage, and the scope is limited to the affected daemon and its privileges.
OpenCVE Enrichment