PT-2025-48360 · Unknown · Ais-Catcher
Jaenact
·
Published
2025-11-29
·
Updated
2025-12-01
·
CVE-2025-66217
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
AIS-catcher versions prior to 0.64
Description
AIS-catcher, a multi-platform AIS receiver, contains a flaw in its MQTT parsing logic. An integer underflow can be triggered by sending a crafted MQTT packet with a modified Topic Length field. This can cause a significant Heap Buffer Overflow, resulting in a Denial of Service (DoS). When used as a library, this can also lead to severe Memory Corruption, potentially enabling Remote Code Execution (RCE). The issue is related to the parsing of the
Topic Length field within MQTT packets.Recommendations
Update to version 0.64 or later.
Exploit
Fix
RCE
DoS
Integer Underflow
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ais-Catcher