CVE-2025-6072: Stack Buffer Overflow in MQTTCore
Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE.
When the REST interface is enabled by the user, and an attacker gains access to the control network, and CVE-2025-6074 is exploited, the attacker can use the JSON configuration to overflow the date of expiration field.This issue affects RMC-100: from 2105457-043 through 2105457-045; RMC-100 LITE: from 2106229-015 through 2106229-016.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6072?
CVE-2025-6072 is classified as a critical severity vulnerability due to its potential for a stack-based buffer overflow.
How do I fix CVE-2025-6072?
To fix CVE-2025-6072, ensure that the REST interface is disabled on affected ABB RMC-100 and ABB RMC-100 LITE devices.
What products are affected by CVE-2025-6072?
CVE-2025-6072 affects ABB RMC-100 and ABB RMC-100 LITE products within specified version ranges.
Can CVE-2025-6072 be exploited remotely?
Yes, CVE-2025-6072 can be exploited remotely if an attacker gains access to the control network with the REST interface enabled.
What can an attacker achieve by exploiting CVE-2025-6072?
Exploiting CVE-2025-6072 allows an attacker to execute arbitrary code by overflowing the stack via the JSON configuration.