CVE Feed

    Dashboard / CVE / CVE-2026-28525

    CVE-2026-28525

    SWUpdate contains an integer underflow vulnerability in the multipart upload parser in mongoose_multipart.c that allows unauthenticated attackers to cause a denial of service by sending a crafted HTTP POST request to /upload with a malformed multipart boundary and controlled TCP stream timing. Attackers can trigger an integer underflow in the mg_http_multipart_continue_wait_for_chunk() function when the buffer length falls within a specific range, causing an out-of-bounds heap read past the allocated receive buffer to a local IPC socket.

    Published:Apr 23, 2026
    Last Modified:Jun 4, 2026
    EPS:Apr 23, 2026
    EPSS Score:0.00053
    CVSS Score:6.8

    Affected Products

    Vendor
    Sbabic
    Product
    Swupdate
    Vendor
    Swupdate
    Product
    Swupdate

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High