CVE-2025-6693

A vulnerability, which was classified as critical, was found in RT-Thread up to 5.1.0. This affects the function sys_device_open/sys_device_read/sys_device_control/sys_device_init/sys_device_close/sys_device_write of the file components/drivers/core/device.c. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://github.com/RT-Thread/rt-thread/issues/10387 Exploit Issue Tracking
https://vuldb.com/?ctiid.313959 Permissions Required VDB Entry
https://vuldb.com/?id.313959 Third Party Advisory VDB Entry
https://vuldb.com/?submit.595813 Third Party Advisory VDB Entry
https://vuldb.com/?submit.595814 Third Party Advisory VDB Entry
https://vuldb.com/?submit.595827 Third Party Advisory VDB Entry
https://vuldb.com/?submit.595869 Third Party Advisory VDB Entry
https://vuldb.com/?submit.595870 Third Party Advisory VDB Entry
https://vuldb.com/?submit.595871 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:rt-thread:rt-thread:*:*:*:*:*:*:*:*

History

11 Jul 2025, 14:27

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-26 13:15

Updated : 2025-07-11 14:27


NVD link : CVE-2025-6693

Mitre link : CVE-2025-6693

CVE.ORG link : CVE-2025-6693


JSON object : View

Products Affected

rt-thread

  • rt-thread
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer