Vulnerability Details CVE-2025-62526
                OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, ubusd contains a heap buffer overflow in the event registration parsing code. This allows an attacker to modify the head and potentially execute arbitrary code in the context of the ubus daemon. The affected code is executed before running the ACL checks, all ubus clients are able to send such messages. In addition to the heap corruption, the crafted subscription also results in a bypass of the listen ACL. This is fixed in OpenWrt 24.10.4. There are no workarounds.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.0
                        
                    
                    
                        
                            EPSS Ranking 1.6%
                        
                    
                 
                
                    CVSS Severity
                    
                        
                            CVSS v3 Score 7.9
                        
                    
                    
                 
                
                
                
                    
                
                
                    
                        Products affected by CVE-2025-62526
                        
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:-
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:15.05.1
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:17.01.0
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:17.01.1
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:17.01.2
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:17.01.3
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:17.01.4
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:17.01.5
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:17.01.6
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:17.01.7
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:18.06.0
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:18.06.1
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:18.06.2
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:18.06.3
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:18.06.4
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:18.06.5
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:18.06.6
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:18.06.7
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:18.06.8
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:18.06.9
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:19.07.0
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:19.07.1
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:19.07.10
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:19.07.2
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:19.07.3
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:19.07.4
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:19.07.5
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:19.07.6
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:19.07.7
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:19.07.8
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:19.07.9
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:21.02
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:21.02.0
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:21.02.1
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:21.02.2
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:21.02.3
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:21.02.4
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:21.02.5
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:21.02.6
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:21.02.7
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:22.03.0
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:22.03.1
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:22.03.2
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:22.03.3
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:22.03.4
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:22.03.5
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:22.03.6
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:22.03.7
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:23.05.0
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:23.05.1
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:23.05.2
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:23.05.3
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:23.05.4
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:23.05.5
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:23.05.6
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:24.10.0
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:24.10.1
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:24.10.2
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:openwrt:openwrt:24.10.3