CVE-2025-8076 Details
Description
There is a vulnerability in the Supermicro BMC web function at Supermicro MBD-X13SEDW-F. After logging into the BMC Web server, an attacker can use a specially crafted payload to trigger the Stack buffer overflow vulnerability.
A stack-based buffer overflow vulnerability has been identified in the Supermicro BMC web function on the MBD-X13SEDW-F motherboard. This vulnerability allows an authenticated attacker to execute arbitrary code on the BMC's firmware operating system. The issue arises in the 'upload_license.cgi' web portal endpoint, where a crafted Content-Type HTTP header can overflow a 128-byte stack buffer, overwrite the return address and registers, and lead to unauthorized code execution.
Supermicro has developed a BMC firmware update to address this vulnerability. Affected users should check the Supermicro Release Notes for the update.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 18, 2025CISA-ADP
Assessed Nov 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.supermicro.com/zh_tw/support/security_BMC_IPMI_Nov_2025 | Super Micro Computer, Inc. | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | Super Micro Computer, Inc. |
Affected Products
| Product | Versions |
|---|---|
| Supermicro MBD-X13SEDW-F | All versions |
CPE
Remediation
| |
| Supermicro BMC | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Super Micro Computer, Inc. |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 18, 2025 | New CVE Received | Super Micro Computer, Inc. |
Volerion