Junglewise Threat Intelligence

CVE-2026-3823: Atop Technologies EHG2408 stack-based buffer overflow

CVE-2026-3823 · Severity: critical · CVSS 9.8 · Published 2026-03-09

Executive brief

Atop Technologies EHG2408 series industrial switches are susceptible to a critical security flaw that allows an unauthorized person to take complete control of the device over the network. These switches are typically used in industrial environments to manage network traffic between critical systems. An attacker could exploit this to disrupt operations, intercept sensitive data, or use the switch as a foothold to attack other parts of the corporate or industrial network.

Technical details

A stack-based buffer overflow vulnerability (CWE-121) exists in the firmware of Atop Technologies EHG2408 and EHG2408-2SFP switches. The flaw allows a remote, unauthenticated attacker to send specially crafted packets to the device to overflow a buffer on the stack. This can be leveraged to hijack the program's execution flow, leading to arbitrary code execution with high privileges. The vulnerability is present in all firmware versions prior to 3.36. Users are advised to update to version 3.36 or later to mitigate this risk.

Affected products

  • Atop Technologies EHG2408 before 3.36
  • Atop Technologies EHG2408-2SFP before 3.36

Timeline

  • 2026-03-09: disclosed
  • 2026-03-09: advisory: TWCERT/CC published advisory TVN-202603004

References