ZDI-25-885: (0Day) Digilent DASYLab DSB File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published Nov 20, 2025
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Digilent DASYLab. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-9188.
Affected Software
1 affected component
Digilent DASYLab
Event History
Nov 20, 2025
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-25-885?
The severity of ZDI-25-885 is critical, allowing remote code execution.
2
How do I fix ZDI-25-885?
To fix ZDI-25-885, update Digilent DASYLab to the latest version provided by the vendor.
3
Who is affected by ZDI-25-885?
ZDI-25-885 affects installations of Digilent DASYLab across all versions.
4
What type of attack does ZDI-25-885 enable?
ZDI-25-885 enables remote attackers to execute arbitrary code.
5
What is required to exploit ZDI-25-885?
Exploitation of ZDI-25-885 requires user interaction, such as visiting a malicious page or opening a malicious file.