CVE-2025-65502: Null Pointer Dereference
Published Nov 24, 2025
·Updated
Null pointer dereference in addcacerts() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of service via TLS initialization where SSLCTXgetcertstore() returns NULL.
Affected Software
2 affected components
Cesanta Mongoose<7.2
Cesanta Mongoose<7.2
Remediation
Patch Available
Event History
Nov 24, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-65502?
CVE-2025-65502 is classified as a denial of service vulnerability.
2
How does CVE-2025-65502 affect the Cesanta Mongoose?
CVE-2025-65502 affects Cesanta Mongoose by allowing remote attackers to trigger a null pointer dereference during TLS initialization.
3
How do I fix CVE-2025-65502?
To fix CVE-2025-65502, upgrade Cesanta Mongoose to version 7.2 or later.
4
What versions of Cesanta Mongoose are vulnerable to CVE-2025-65502?
Versions of Cesanta Mongoose prior to 7.2 are vulnerable to CVE-2025-65502.
5
Can CVE-2025-65502 be exploited remotely?
Yes, CVE-2025-65502 can be exploited remotely by attackers to cause a denial of service.