CVE-2025-47869 is a critical buffer overflow vulnerability in the Apache NuttX RTOS XMLRPC example application (versions 6.22 to before 12.9.0), stemming from an improper restriction of operations within a memory buffer. This flaw, rated 9.8 Critical (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), allows unauthenticated remote attackers to achieve remote code execution or device crashes due to hardcoded buffer sizes in the device stats structure. There is currently no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available, though it has garnered some community discussion. Users are advised to review their code for this pattern and update buffer sizes as demonstrated in version 12.9.0.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.22, < 12.9.0CPE matchmatch criteria | cpe:2.3:a:apache:nuttx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.