RT-Thread is an embedded real-time operating system widely used in IoT and embedded devices, with its vulnerability footprint concentrated in the core RTOS product. The observed disclosures reflect the complexity inherent to kernel-level firmware, though the specific weakness patterns remain to be firmly established across a broader sample. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rt Thread over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-5868CRITICAL A vulnerability, which was classified as critical, has been found in RT-Thread 5.1.0. This issue affects the function sys_thread_sigprocmask of the file rt-thread/components/lwp/lw | Jun 9, 2025 | 9.8 | 30 | NO | NO |
CVE-2024-25393CRITICAL A stack buffer overflow occurs in net/at/src/at_server.c in RT-Thread through 5.0.2. | Mar 27, 2024 | 9.8 | 30 | NO | NO |
CVE-2025-5869CRITICAL A vulnerability, which was classified as critical, was found in RT-Thread 5.1.0. Affected is the function sys_recvfrom of the file rt-thread/components/lwp/lwp_syscall.c. The manip | Jun 9, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-5867CRITICAL A vulnerability classified as critical was found in RT-Thread 5.1.0. This vulnerability affects the function csys_sendto of the file rt-thread/components/lwp/lwp_syscall.c. The man | Jun 9, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-5866CRITICAL A vulnerability classified as critical has been found in RT-Thread 5.1.0. This affects the function sys_sigprocmask of the file rt-thread/components/lwp/lwp_syscall.c. The manipula | Jun 9, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-5865CRITICAL A vulnerability was found in RT-Thread 5.1.0. It has been rated as critical. Affected by this issue is the function sys_select of the file rt-thread/components/lwp/lwp_syscall.c of | Jun 9, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-6693HIGH A vulnerability, which was classified as critical, was found in RT-Thread up to 5.1.0. This affects the function sys_device_open/sys_device_read/sys_device_control/sys_device_init/ | Jun 26, 2025 | 7.8 | 24 | NO | NO |
CVE-2024-25395HIGH A buffer overflow occurs in utilities/rt-link/src/rtlink.c in RT-Thread through 5.0.2. | Mar 27, 2024 | 8.8 | 22 | NO | NO |
CVE-2024-25391HIGH A stack buffer overflow occurs in libc/posix/ipc/mqueue.c in RT-Thread through 5.0.2. | Mar 27, 2024 | 8.4 | 22 | NO | NO |
CVE-2024-25390HIGH A heap buffer overflow occurs in finsh/msh_file.c and finsh/msh.c in RT-Thread through 5.0.2. | Mar 27, 2024 | 8.4 | 22 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rt Thread.
Media articles that mention a CVE ID that affects a product developed by Rt Thread — matched by CVE ID, not by vendor name.