CVE-2025-62526 Details
Description
OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, ubusd contains a heap buffer overflow in the event registration parsing code. This allows an attacker to modify the head and potentially execute arbitrary code in the context of the ubus daemon. The affected code is executed before running the ACL checks, all ubus clients are able to send such messages. In addition to the heap corruption, the crafted subscription also results in a bypass of the listen ACL. This is fixed in OpenWrt 24.10.4. There are no workarounds.
A heap buffer overflow vulnerability has been identified in the OpenWrt ubus daemon's event registration parsing code, in versions prior to 24.10.4. This vulnerability allows an attacker to manipulate memory and potentially execute arbitrary code within the context of the ubus daemon. The issue arises because the vulnerable code is executed before access control list (ACL) checks are applied, enabling all ubus clients to send messages that exploit this flaw. Additionally, the crafted subscription can bypass the listen ACL, further exacerbating the issue.
Users can upgrade to OpenWrt version 24.10.4 or later to address this vulnerability. This includes snapshot builds released after October 18, 2025. For those on older OpenWrt versions like 23.05 or 22.03, which are no longer supported, an upgrade to a version that receives security updates is recommended.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-122 | Heap-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openwrt openwrt | < 24.10.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 30, 2025 | Initial Analysis | [email protected] |
| Oct 22, 2025 | New CVE Received | [email protected] |