CVE-2026-9805: CWE-787 Out-of-bounds write in Insyde Software InsydeH2O
Description
CVE-2026-9805 is a low-severity vulnerability in Insyde Software's InsydeH2O firmware. It involves an out-of-bounds write in the SMM IHISI command handler for the FMTS command 0x32, where data is read and written without proper buffer size checks, potentially causing a buffer overflow.
CVSS v3.1
Score 2.7low
Affected software
Insyde Software
InsydeH2O
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-787) affects the SMM IHISI command handler function FMTSWriteUseIntelLib in InsydeH2O firmware. The handler processes the FMTS command 0x32 by reading and writing data without validating the buffer size, which can lead to an out-of-bounds write condition. The CVSS 3.1 base score is 2.7, indicating low severity, with attack vector requiring physical presence (AV:P), high attack complexity (AC:H), high privileges (PR:H), and user interaction (UI:R). The impact includes low integrity and low availability impact but no confidentiality impact. No patch or remediation information is currently available, and no known exploits are reported in the wild.
Potential Impact
The vulnerability could allow an attacker with high privileges and physical access to cause a buffer overflow via the FMTS command 0x32 in the SMM IHISI command handler. This may result in limited integrity and availability impact on the affected system. Confidentiality is not impacted. Due to the required conditions (physical access, high privileges, user interaction), the overall risk is low.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or mitigation is currently documented. Until a patch is available, limit physical access to affected systems and restrict high-privilege operations involving the FMTS command 0x32 if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Insyde
- Date Reserved
- 2026-05-28T06:24:59.358Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a8e3fe5acd9273b490ffd28
Added to database: 08/26/2026, 01:22:45 UTC
Last enriched: 09/10/2026, 12:23:33 UTC
Last updated: 10/09/2026, 06:48:21 UTC
Views: 66
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.