CVE-2025-49604

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-49604
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-49604.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-49604
Published
2025-07-09T16:15:24.137Z
Modified
2025-11-17T03:58:53.924904Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

For Realtek AmebaD devices, a heap-based buffer overflow was discovered in Ameba-AIoT ameba-arduino-d before version 3.1.9 and ameba-rtos-d before commit c2bfd8216a1cbc19ad2ab5f48f372ecea756d67a on 2025/07/03. In the WLAN driver defragment function, lack of validation of the size of fragmented Wi-Fi frames may lead to a heap-based buffer overflow.

References

Affected packages

Git / github.com/ameba-aiot/ameba-arduino-d

Affected ranges

Type
GIT
Repo
https://github.com/ameba-aiot/ameba-arduino-d
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

V3.*

V3.0.10-v02
V3.0.11
V3.0.5
V3.0.6
V3.0.7
V3.0.8-V04
V3.0.9
V3.1.0
V3.1.1
V3.1.3
V3.1.4
V3.1.5
V3.1.6
V3.1.6-V02
V3.1.7
V3.1.8