CVE-2025-49604: Buffer Overflow

Published Jul 9, 2025
·
Updated

For Realtek AmebaD devices, a heap-based buffer overflow was discovered in Ameba-AIoT ameba-arduino-d before version 3.1.9 and ameba-rtos-d before commit c2bfd8216a1cbc19ad2ab5f48f372ecea756d67a on 2025/07/03. In the WLAN driver defragment function, lack of validation of the size of fragmented Wi-Fi frames may lead to a heap-based buffer overflow.

Other sources

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

NVD

Affected Software

2 affected components
Realtek Ameba-AIoT ameba-arduino-d<3.1.9
Realtek Ameba-AIoT ameba-rtos-d<c2bfd8216a1cbc19ad2ab5f48f372ecea756d67a

Event History

Jul 9, 2025
CVE Published
via MITRE·12:00 AM
Rejected
via MITRE·12:00 AM
Data Sourced
via NVD·04:15 PM
Description
Jul 22, 2025
Rejected
via MITRE·02:22 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-49604?

CVE-2025-49604 is classified as a critical severity vulnerability due to its potential to cause a buffer overflow.

2

How do I fix CVE-2025-49604?

To address CVE-2025-49604, upgrade Realtek Ameba-AIoT ameba-arduino-d to version 3.1.9 or later and ameba-rtos-d to the specified commit.

3

What components are impacted by CVE-2025-49604?

CVE-2025-49604 affects Realtek Ameba-AIoT ameba-arduino-d versions prior to 3.1.9 and ameba-rtos-d versions prior to the specified commit.

4

What are the consequences of CVE-2025-49604?

If exploited, CVE-2025-49604 could lead to arbitrary code execution due to a buffer overflow in the WLAN driver.

5

When was CVE-2025-49604 discovered?

CVE-2025-49604 was discovered on July 3, 2025.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203