CVE-2025-4582 Details
Description
Buffer Over-read, Off-by-one Error vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation, Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.0.0 before 7.3.0.8, from 6.1.0 before 6.1.2.26, from 6.0.0 before 6.0.1.43, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from 4.4a before 5.1.*.
A buffer over-read and off-by-one error vulnerability has been identified in RTI Connext Professional Core Libraries. This vulnerability allows for file manipulation and affects multiple versions across the 4.x to 7.5.0 range. The issue arises when the application parses malicious license strings or XML documents, leading to potential memory corruption, application crashes, and unauthorized access to sensitive information.
Users can protect access to the file system by restricting permissions on files being loaded by the Connext application. For version 7.3.0, a patch is available on the RTI Customer Portal. Users can also contact RTI Support to arrange for a patch on other versions and architectures.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.rti.com/vulnerabilities/#cve-2025-4582 | RTI | MitigationVendor Advisory |
Weakness Enumeration
Affected Products
| Product | Versions |
|---|---|
| rti connext professional | >= 4.4a, < 6.1.2.26 >= 7.0.0, < 7.3.0.8 >= 7.4.0, < 7.6.0 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 22, 2026 | CVE Modified | RTI |
| Jun 17, 2026 | CVE Modified | RTI |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 1, 2026 | CVE Modified | RTI |
| Dec 16, 2025 | CVE Modified | RTI |
| Oct 2, 2025 | Initial Analysis | [email protected] |
| Sep 30, 2025 | CVE Modified | RTI |
| Sep 23, 2025 | New CVE Received | RTI |