A vulnerability was found in RE11S 1.11. It has been declared as critical. This vulnerability affects the function
setWAN
. The manipulation of the argument pptpUserName leads to stack-based buffer overflow.
This vulnerability was named CVE-2025-22904. Access to the local network is required for this attack to succeed. There is no exploit available.