← volver
CVE-2025-66217

AIS-catcher Integer Underflow in MQTT Packet Parsing leading to Heap Buffer Overflow

CVSS 8.8 HIGHEPSS 0.6%CWE-122CWE-191
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.8EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
29 nov 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, an integer underflow vulnerability exists in the MQTT parsing logic of AIS-catcher. This vulnerability allows an attacker to trigger a massive Heap Buffer Overflow by sending a malformed MQTT packet with a manipulated Topic Length field. This leads to an immediate Denial of Service (DoS) and, when used as a library, severe Memory Corruption that can be leveraged for Remote Code Execution (RCE). This issue has been patched in version 0.64.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
jvde-github · AIS-catcher

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →