NewStart CGSL MAIN 7.02 : libsoup Multiple Vulnerabilities (NS-SA-2026-0100)

high Nessus Plugin ID 343555

Synopsis

The remote NewStart CGSL host is affected by multiple vulnerabilities.

Description

The remote NewStart CGSL host, running version MAIN 7.02, has libsoup packages installed that are affected by multiple vulnerabilities:

- A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overread. This can allow an attacker to potentially access sensitive information or cause an application level denial of service. (CVE-2026-2369)

- GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\0' characters at the end of header names are ignored, i.e., a Transfer-Encoding\0: chunked header is treated the same as a Transfer-Encoding: chunked header. (CVE-2024-52530)

- A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the library may perform an out-of-bounds memory read. This flaw could result in unintended disclosure of memory contents, potentially exposing sensitive information from the process using libsoup.
(CVE-2025-11021)

- A flaw in libsoup's HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.
(CVE-2025-14523)

- A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server. (CVE-2025-2784)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the vulnerable CGSL libsoup packages. Note that updated packages may not be available yet. Please contact ZTE for more information.

See Also

https://security.gd-linux.com/info/CVE-2024-52530

https://security.gd-linux.com/info/CVE-2025-11021

https://security.gd-linux.com/info/CVE-2025-14523

https://security.gd-linux.com/info/CVE-2025-2784

https://security.gd-linux.com/info/CVE-2025-32049

https://security.gd-linux.com/info/CVE-2025-32050

https://security.gd-linux.com/info/CVE-2025-32052

https://security.gd-linux.com/info/CVE-2025-32053

https://security.gd-linux.com/info/CVE-2025-32906

https://security.gd-linux.com/info/CVE-2025-32907

https://security.gd-linux.com/info/CVE-2025-32909

https://security.gd-linux.com/info/CVE-2025-32910

https://security.gd-linux.com/info/CVE-2025-32912

https://security.gd-linux.com/info/CVE-2025-32914

https://security.gd-linux.com/info/CVE-2025-4476

https://security.gd-linux.com/info/CVE-2025-46420

https://security.gd-linux.com/info/CVE-2025-46421

https://security.gd-linux.com/info/CVE-2025-4945

https://security.gd-linux.com/info/CVE-2025-4948

https://security.gd-linux.com/info/CVE-2025-4969

https://security.gd-linux.com/info/CVE-2026-0719

https://security.gd-linux.com/info/CVE-2026-1539

https://security.gd-linux.com/info/CVE-2026-1760

https://security.gd-linux.com/info/CVE-2026-1761

https://security.gd-linux.com/info/CVE-2026-1801

https://security.gd-linux.com/info/CVE-2026-2369

https://security.gd-linux.com/info/CVE-2026-6324

https://security.gd-linux.com/notice/NS-SA-2026-0100

Plugin Details

Severity: High

ID: 343555

File Name: newstart_cgsl_NS-SA-2026-0100_libsoup.nasl

Version: 1.1

Type: Local

Published: 9/8/2026

Updated: 9/8/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.23

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:C

CVSS Score Source: CVE-2026-2369

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.8

Threat Score: 7.8

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L

CVSS Score Source: CVE-2026-1761

Vulnerability Information

CPE: cpe:/o:zte:cgsl_main:7, p-cpe:/a:zte:cgsl_main:libsoup-devel, p-cpe:/a:zte:cgsl_main:libsoup-doc, p-cpe:/a:zte:cgsl_main:libsoup

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/ZTE-CGSL/release, Host/ZTE-CGSL/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/7/2026

Vulnerability Publication Date: 11/11/2024

Reference Information

CVE: CVE-2024-52530, CVE-2025-11021, CVE-2025-14523, CVE-2025-2784, CVE-2025-32049, CVE-2025-32050, CVE-2025-32052, CVE-2025-32053, CVE-2025-32906, CVE-2025-32907, CVE-2025-32909, CVE-2025-32910, CVE-2025-32912, CVE-2025-32914, CVE-2025-4476, CVE-2025-46420, CVE-2025-46421, CVE-2025-4945, CVE-2025-4948, CVE-2025-4969, CVE-2026-0719, CVE-2026-1539, CVE-2026-1760, CVE-2026-1761, CVE-2026-1801, CVE-2026-2369, CVE-2026-6324

IAVA: 2025-A-0780-S, 2026-A-0139-S, 2026-A-0165-S