CVE-2023-35802: Extremenetworks Iq Engine

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of the CAPWAP protocol that may be exploited to obtain elevated privileges to conduct remote code execution. Access to the internal management interface/subnet is required to conduct the exploit.

Affected products

  • Extremenetworks Iq Engine: before 10.6r1 (fixed in 10.6r1); before 10.6r5 (fixed in 10.6r5)

Published 2023-07-15. Last modified 2026-06-17.