CVE-2025-48769 is a Use After Free vulnerability in the Apache NuttX RTOS, specifically within the fs/vfs/fs_rename code, affecting versions from 7.20 before 12.11.0. This flaw allows for arbitrary buffer reallocation and writes to freed heap memory due to recursive implementation and shared buffer pointers, potentially leading to unintended virtual filesystem rename/move operations. With a CVSS score of 8.1 (High), this vulnerability can be exploited remotely with low privileges and no user interaction, resulting in high integrity and availability impacts. There is currently no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.20, < 12.11.0CPE matchmatch criteria | cpe:2.3:a:apache:nuttx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.