CVE-2025-10392: Mercury KM08-708h Giga Wifi WAVE2
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
A vulnerability was detected in Mercury KM08-708H GiGA WiFi Wave2 1.1.14. This affects an unknown function of the component HTTP Header Handler. The manipulation of the argument Host results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.
Affected products
- Mercury KM08-708h Giga Wifi WAVE2: version 1.1.14 only
Published 2025-09-14. Last modified 2026-06-17.