CVE-2025-29329 Details
Description
Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote attacker to execute arbitrary code by sending a crafted HTTP request.
A buffer overflow vulnerability has been identified in the Internet Printing Protocol (IPP) service of the Sagemcom F@st 3686 router, specifically in the MAGYAR_4.121.0 version. This vulnerability allows remote attackers to execute arbitrary code by sending crafted HTTP requests. The issue arises because the IPP service, enabled by default, improperly handles the 'Expect' HTTP header, allowing data to be written outside the bounds of a fixed-size array. The vulnerability is exacerbated by the absence of modern security features in the 'ippprint' binary, such as Position Independent Executable (PIE) support, Non-Executable (NX) stack protection, and stack canaries, which could have mitigated the impact of the buffer overflow.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/SilverS3c/Sagemcom-fast-3686-ippprint | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| sagemcom f@st 3686 firmware | 4.121.0 |
CPE
Remediation
| |
| sagemcom f@st 3686 | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jan 22, 2026 | Initial Analysis | [email protected] |
| Jan 13, 2026 | CVE Modified | CISA-ADP |
| Jan 12, 2026 | New CVE Received | [email protected] |