CVE-2025-34458 is a denial-of-service vulnerability affecting wb2osz/direwolf (Dire Wolf) versions up to and including 1.8. A remote, unauthenticated attacker can trigger an assertion failure in the APRS MIC-E decoder by sending a specially crafted AX.25 frame with an empty or truncated comment field, causing immediate process termination. This vulnerability has a high CVSS score of 8.7, indicating a severe impact on availability with low attack complexity and no user interaction required. There is currently no evidence of active exploitation, nor are there public exploit tools or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Wb2osz | Dire Wolf | >= 0, <= 1.8.1CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.