Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-103436

Quick assessment

Affected
apcupsd apcupsd
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

apcupsd 3.14.14 及更早版本在 中的 函数存在未初始化栈内存泄露漏洞。该函数被 、 和 使用。在单字段处理路径中,如果匹配的 STATUS 行包含的空白分隔令牌少于三个, 不会执行任何赋值操作,但函数仍返回成功状态。因此,调用者会将未初始化的目标缓冲区内容输出到 HTTP 响应中,导致敏感信息泄露。

CVSS 3.7 · Low EPSS 0.29% · P20

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
apcupsd apcupsd ≤ 3.14.14 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-103436

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
apcupsd through 3.14.14 discloses uninitialized stack memory in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi. On the single-field path, when the matched STATUS line has fewer than three whitespace-separated tokens, sscanf("%*s %*s %s", answer) performs no assignment but the function returns success, and thus the caller prints the uninitialized destination buffer into the HTTP response.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用未经初始化的变量
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
apcupsd apcupsd 0 ~ 3.14.14 -

II. Public POCs for CVE-2026-103436

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-103436

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-103436 (1)

Other References for CVE-2026-103436 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-103436

No comments yet


Leave a comment