216.73.216.233

CVE-2025-66217

· Published 29/11/2025 03:15 · Modified 23/12/2025 16:10

Labels: CVE-2025-66217 2025-11-29CVE-2025-66217CWE-122CWE-191[email protected]

Essential information

Published
29/11/2025 03:15
Modified
23/12/2025 16:10
Author
Creator
CVSS
8.8 HIGH (v3) 8.8 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, an integer underflow vulnerability exists in the MQTT parsing logic of AIS-catcher. This vulnerability allows an attacker to trigger a massive Heap Buffer Overflow by sending a malformed MQTT packet with a manipulated Topic Length field. This leads to an immediate Denial of Service (DoS) and, when used as a library, severe Memory Corruption that can be leveraged for Remote Code Execution (RCE). This issue has been patched in version 0.64.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
aiscatcher / ais-catcher cpe:2.3:a:aiscatcher:ais-catcher:*:*:*:*:*:*:*:*

References