CVE-2026-33847

7.8

Linkingvision · rapidvms

A buffer handling vulnerability in Linkingvision rapidvms allows for potential memory corruption, which may lead to high impact on system integrity, availability, and confidentiality.

Executive summary

A critical memory buffer vulnerability in Linkingvision rapidvms, identified as CWE-119, exposes systems to potential compromise through memory corruption.

Vulnerability

This vulnerability involves an improper restriction of operations within the bounds of a memory buffer (CWE-119). The flaw can be triggered by an unauthenticated attacker, although it requires user interaction as indicated by the CVSS vector.

Business impact

The exploitation of this memory corruption flaw can lead to a total loss of confidentiality, integrity, and availability for the affected system. Given the CVSS score of 7.8, this is a High severity issue that could allow an attacker to execute arbitrary code or crash critical services, leading to significant operational disruption and data exposure.

Remediation

Immediate Action: Users should update to the version identified in PR#96 or the latest available release provided by the vendor. If an update is not immediately feasible, restrict access to the rapidvms interface to trusted internal networks only.

Proactive Monitoring: Monitor system logs for unusual crash reports or unexpected service restarts that may indicate attempted exploitation of memory-related flaws.

Compensating Controls: Deploy network-level access controls to limit exposure of the rapidvms service to untrusted entities, reducing the likelihood of a successful attack.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The vulnerability represents a significant risk to the security posture of the affected infrastructure. Organizations should prioritize the application of the vendor fix described in PR#96 to eliminate the underlying memory safety issue. Failure to address this vulnerability increases the risk of unauthorized system access and service instability.

More Linkingvision CVEs

Sources

Originally found and disclosed by TITAN Team (titancaproject@gmail.com), per the CVE Program record.