PT-2025-25490 · Apache · Apache Nuttx Rtos

Jianyuwang

·

Published

2025-06-14

·

Updated

2025-06-16

·

CVE-2025-47869

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache NuttX RTOS versions 6.22 through 12.9.0
Description An issue was discovered in the Apache NuttX RTOS apps/examples/xmlrpc application, where a device stats structure stored remotely provided parameters with a hardcoded buffer size, potentially leading to a buffer overflow. The structure members' buffers were updated to a valid size of CONFIG XMLRPC STRINGSIZE+1. This issue may affect users who have based their code on the example application from releases prior to 12.9.0.
Recommendations For Apache NuttX RTOS versions 6.22 through 12.9.0, users are advised to review their code for the pattern of hardcoded buffer sizes and update the buffer sizes as presented in the example application in release 12.9.0.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-08200
CVE-2025-47869

Affected Products

Apache Nuttx Rtos