CVE-2025-49604: Buffer Overflow
For Realtek AmebaD devices, a heap-based buffer overflow was discovered in Ameba-AIoT ameba-arduino-d before version 3.1.9 and ameba-rtos-d before commit c2bfd8216a1cbc19ad2ab5f48f372ecea756d67a on 2025/07/03. In the WLAN driver defragment function, lack of validation of the size of fragmented Wi-Fi frames may lead to a heap-based buffer overflow.
Other sources
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
— NVD
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49604?
CVE-2025-49604 is classified as a critical severity vulnerability due to its potential to cause a buffer overflow.
How do I fix CVE-2025-49604?
To address CVE-2025-49604, upgrade Realtek Ameba-AIoT ameba-arduino-d to version 3.1.9 or later and ameba-rtos-d to the specified commit.
What components are impacted by CVE-2025-49604?
CVE-2025-49604 affects Realtek Ameba-AIoT ameba-arduino-d versions prior to 3.1.9 and ameba-rtos-d versions prior to the specified commit.
What are the consequences of CVE-2025-49604?
If exploited, CVE-2025-49604 could lead to arbitrary code execution due to a buffer overflow in the WLAN driver.
When was CVE-2025-49604 discovered?
CVE-2025-49604 was discovered on July 3, 2025.