CVE Explorer
CVE-2025-62526
OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, ubusd contains a heap buffer overflow in the event registration parsing code. This allows an attacker to modify the head and potentially execute arbitrary code in the context of the ubus daemon. The affected code is executed before running the ACL checks, all ubus clients are able to send such messages. In addition to the heap corruption, the crafted subscription also results in a bypass of the list
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"openwrt","vendor":"openwrt","versions":[{"status":"affected","version":"< 24.10.4"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:cc12e0e6d925e466cbcbc7034b16887e46e8089f6c3a978e0878b3d38ee3ec7f · sha256:5012d75f66fc7ebc… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.9,"baseSeverity":"HIGH","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:cc12e0e6d925e466cbcbc7034b16887e46e8089f6c3a978e0878b3d38ee3ec7f · sha256:5012d75f66fc7ebc… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-122","description":"CWE-122: Heap-based Buffer Overflow","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:cc12e0e6d925e466cbcbc7034b16887e46e8089f6c3a978e0878b3d38ee3ec7f · sha256:5012d75f66fc7ebc… · /containers/cna/problemTypes/0/descriptions/0
Source references
7 source assertions{"name":"https://github.com/openwrt/openwrt/commit/4b907e69ea58fc0ba35fd1755dc4ba22262af3a4","tags":["x_refsource_MISC"],"url":"https://github.com/openwrt/openwrt/commit/4b907e69ea58fc0ba35fd1755dc4ba22262af3a4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cc12e0e6d925e466cbcbc7034b16887e46e8089f6c3a978e0878b3d38ee3ec7f · sha256:5012d75f66fc7ebc… · /containers/cna/references/1
{"name":"https://github.com/openwrt/openwrt/commit/a7901969932a175cded3c93bdeb65f32ed3705e6","tags":["x_refsource_MISC"],"url":"https://github.com/openwrt/openwrt/commit/a7901969932a175cded3c93bdeb65f32ed3705e6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cc12e0e6d925e466cbcbc7034b16887e46e8089f6c3a978e0878b3d38ee3ec7f · sha256:5012d75f66fc7ebc… · /containers/cna/references/2
{"name":"https://github.com/openwrt/openwrt/security/advisories/GHSA-cp32-65v4-cp73","tags":["x_refsource_CONFIRM"],"url":"https://github.com/openwrt/openwrt/security/advisories/GHSA-cp32-65v4-cp73"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cc12e0e6d925e466cbcbc7034b16887e46e8089f6c3a978e0878b3d38ee3ec7f · sha256:5012d75f66fc7ebc… · /containers/cna/references/0
{"name":"https://github.com/openwrt/ubus/commit/60e04048a0e2f3e33651c19e62861b41be4c290f","tags":["x_refsource_MISC"],"url":"https://github.com/openwrt/ubus/commit/60e04048a0e2f3e33651c19e62861b41be4c290f"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cc12e0e6d925e466cbcbc7034b16887e46e8089f6c3a978e0878b3d38ee3ec7f · sha256:5012d75f66fc7ebc… · /containers/cna/references/3
{"name":"https://github.com/openwrt/ubus/commit/aa4a7ee1d3417bc11207ad0a78d579ece7fe0c13","tags":["x_refsource_MISC"],"url":"https://github.com/openwrt/ubus/commit/aa4a7ee1d3417bc11207ad0a78d579ece7fe0c13"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cc12e0e6d925e466cbcbc7034b16887e46e8089f6c3a978e0878b3d38ee3ec7f · sha256:5012d75f66fc7ebc… · /containers/cna/references/4
{"name":"https://github.com/openwrt/ubus/commit/d31effb4277bd557f5ccf16d909422718c1e49d0","tags":["x_refsource_MISC"],"url":"https://github.com/openwrt/ubus/commit/d31effb4277bd557f5ccf16d909422718c1e49d0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cc12e0e6d925e466cbcbc7034b16887e46e8089f6c3a978e0878b3d38ee3ec7f · sha256:5012d75f66fc7ebc… · /containers/cna/references/5
{"name":"https://openwrt.org/advisory/2025-10-22-1","tags":["x_refsource_MISC"],"url":"https://openwrt.org/advisory/2025-10-22-1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cc12e0e6d925e466cbcbc7034b16887e46e8089f6c3a978e0878b3d38ee3ec7f · sha256:5012d75f66fc7ebc… · /containers/cna/references/6
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.