PT-2025-54473 · Apache · Apache Nuttx Rtos

Published

2025-12-31

·

Updated

2026-01-06

·

CVE-2025-48768

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache NuttX RTOS versions 10.0.0 through 12.9.9
Description A flaw exists in the fs/inode/fs inoderemove code of the Apache NuttX RTOS that allows root filesystem inode removal. This can lead to a debug assert trigger (disabled by default), a NULL pointer dereference (handling varies by architecture), or a Denial of Service. Users of filesystem-based services with write access exposed over the network (such as FTP) may be affected.
Recommendations Upgrade to version 12.10.0 to resolve the issue.

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2025-48768

Affected Products

Apache Nuttx Rtos