CVE-2025-6693
A vulnerability, which was classified as critical, was found in RT-Thread up to 5.1.0.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.25%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability, which was classified as critical, was found in RT-Thread up to 5.1.0. This affects the function sys_device_open/sys_device_read/sys_device_control/sys_device_init/sys_device_close/sys_device_write of the file components/drivers/core/device.c. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The vendor was contacted early about this disclosure but did not respond in any way.
- CVSS 4.0
- 8.5 HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.25% probability · 16th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- rt-thread/rt-thread
- Source
- cna@vuldb.com
References
- https://github.com/RT-Thread/rt-thread/issues/10387Exploit, Issue Tracking
- https://vuldb.com/?ctiid.313959Permissions Required, VDB Entry
- https://vuldb.com/?id.313959Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.595813Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.595814Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.595827Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.595869Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.595870Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.595871Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.