【資安漏洞預警】上尚科技|EHG2408系列交換器 - Stack-based Buffer Overflow
[Security Vulnerability Alert] Atop | EHG2408 Series Switch - Stack-based Buffer Overflow

發布單位:圖資處數位服務組
日期範圍:2026/3/11 ~ 2026/9/11
 
發布單位:圖資處數位服務組
日期範圍:2026/3/11 ~ 2026/9/11
行政 行政公告
全體

轉發 台灣電腦網路危機處理暨協調中心 資安訊息警訊 TWCERTCC-200-202603-00000006

[內容說明]
【上尚科技|EHG2408系列交換器 - Stack-based Buffer Overflow】(CVE-2026-3823,CVSS:9.8) 上尚科技開發之EHG2408系列交換器存在Stack-based Buffer Overflow漏洞,未經身分鑑別之遠端攻擊者可控制程式執行流程進而執行任意程式碼。

[影響平台]
EHG2408/EHG2408-2SFP韌體v3.36(不含)以前版本

[建議措施]
請更新韌體至v3.36(含)以後版本

[參考資料]
1. https://www.twcert.org.tw/tw/cp-132-10752-5a4d9-1.html

Forwarded from Taiwan Computer Network Crisis Management and Coordination Center: Cybersecurity Alert TWCERTCC-200-202603-00000006

[Content Description]
【Atop | EHG2408 Series Switch - Stack-based Buffer Overflow】(CVE-2026-3823, CVSS: 9.8) Atop EHG2408 series switches contain a Stack-based Buffer Overflow vulnerability. An unauthenticated remote attacker could control the program execution flow and execute arbitrary code.

[Affected Platforms]
EHG2408/EHG2408-2SFP firmware versions prior to v3.36 (excluding v3.36)

[Recommended Action]
Please update the firmware to v3.36 (inclusive) or later.

[References]
1. https://www.twcert.org.tw/tw/cp-132-10752-5a4d9-1.html


相關附件
system_update_alt參考資料
Top↑