PT-2025-33453 · Px4 · Px4-Autopilot

0X20Z

·

Published

2025-08-15

·

Updated

2025-08-15

·

CVE-2025-9020

CVSS v3.1

4.5

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: PX4 PX4-Autopilot versions through 1.15.4
Description: A use-after-free issue exists in the MavlinkReceiver::handle message serial control function within the src/modules/mavlink/mavlink receiver.cpp file of the Mavlink Shell Closing Handler component. The manipulation of the mavlink shell argument leads to this condition. An attack requires local access and is considered difficult to exploit.
Recommendations: Apply the patch with identifier 4395d4f00c49b888f030f5b43e2a779f1fa78708 to resolve this issue.

Fix

Use After Free

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-9020

Affected Products

Px4-Autopilot