CVE-2025-6073: Stack Buffer Overflow in MQTTCore
Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE.
When the REST interface is enabled by the user, and an attacker gains access to the control network, and user/password broker authentication is enabled, and CVE-2025-6074 is exploited, the attacker can overflow the buffer for username or password.
This issue affects RMC-100: from 2105457-043 through 2105457-045; RMC-100 LITE: from 2106229-015 through 2106229-016.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6073?
CVE-2025-6073 is considered a critical stack-based buffer overflow vulnerability that can allow an attacker to execute arbitrary code.
How do I fix CVE-2025-6073?
To mitigate CVE-2025-6073, disable the REST interface if not needed and update to the latest version of the affected software.
What products are affected by CVE-2025-6073?
The affected products for CVE-2025-6073 include ABB RMC-100 versions 2105457-043 to 2105457-045 and ABB RMC-100 LITE versions 2106229-015 to 2106229-016.
What conditions need to be met for CVE-2025-6073 to be exploited?
CVE-2025-6073 can be exploited when the REST interface is enabled, user/password broker authentication is in place, and CVE-2025-6074 is also exploited.
What is the potential impact of CVE-2025-6073?
The potential impact of CVE-2025-6073 includes unauthorized access and execution of arbitrary code within the affected ABB devices.