Impact
A heap buffer overflow exists in the agentlink_server component of Vinchin Backup & Recovery. The vulnerability is triggered by an unchecked body_len field in a TCP packet, allowing an unauthenticated remote attacker to send a malicious payload that is passed directly to recv(), causing an overflow of up to roughly 4 GiB. This can corrupt heap memory, leading to a process crash or, if crafted with precision, to more severe memory corruption that could alter application behavior. The weakness is classified as CWE‑787.
Affected Systems
The affected product line is Vinchin Backup & Recovery 9.0, with all builds up to and including version 9.0.0.86562 vulnerable. The agentlink_server service is the specific entry point; any host running this service in a 9.0 build is at risk.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The EPSS score of < 1 % suggests a very low but non‑zero probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Because it is remotely exploitable without authentication and requires only network connectivity to the agentlink_server port, exposed deployments could suffer denial‑of‑service or exploit memory corruption if an attacker gains sufficient control.
OpenCVE Enrichment