Vulnerability in FastCGI bundled with DeviceGateway

Security Advisory ID
SA-2026-002
Published
2026-05-01
Last Updated
2026-05-01

Vulnerability Details

The following vulnerability exists in the FastCGI library (FastCGI Project) bundled with DeviceGateway. If exploited, an attacker may corrupt system memory and execute arbitrary code.

CVE ID CVSS v3.1 Base Score Description References
CVE-2025-23016 9.3 (Critical) Heap buffer overflow in FastCGI NVD

Affected Products

Product Affected Versions
DeviceGateway Ver. 3.6.1 and earlier

Fixed Versions

Product Fixed Version
DeviceGateway Ver. 3.6.2

Contact

fa-support@takebishi.co.jp

Revision History

← Back to list