PT-2025-54473 · Apache · Apache Nuttx Rtos

CVE-2025-48768

·

Published

2025-12-31

·

Updated

2026-01-06

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache NuttX RTOS versions 10.0.0 through 12.9.9
Description A flaw exists in the fs/inode/fs inoderemove code of the Apache NuttX RTOS that allows root filesystem inode removal. This can lead to a debug assert trigger (disabled by default), a NULL pointer dereference (handling varies by architecture), or a Denial of Service. Users of filesystem-based services with write access exposed over the network (such as FTP) may be affected.
Recommendations Upgrade to version 12.10.0 to resolve the issue.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-48768

Affected Products

Apache Nuttx Rtos