CVE-2025-49604

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVSS

No CVSS.

References

No reference.

Configurations

No configuration.

History

22 Jul 2025, 15:15

Type Values Removed Values Added
References
  • {'url': 'https://github.com/Ameba-AIoT/ameba-arduino-d/pull/281', 'name': 'https://github.com/Ameba-AIoT/ameba-arduino-d/pull/281', 'tags': ['Patch'], 'refsource': ''}
  • {'url': 'https://www.amebaiot.com/en/security-bulletin-cve-2025-49604/', 'name': 'https://www.amebaiot.com/en/security-bulletin-cve-2025-49604/', 'tags': ['Broken Link'], 'refsource': ''}
  • {'url': 'https://github.com/Ameba-AIoT/ameba-arduino-d/releases/tag/V3.1.9', 'name': 'https://github.com/Ameba-AIoT/ameba-arduino-d/releases/tag/V3.1.9', 'tags': ['Release Notes'], 'refsource': ''}
CPE cpe:2.3:a:realtek:ameba-rtos-d:*:*:*:*:*:*:*:*
cpe:2.3:a:realtek:ameba_arduino_sdk:*:*:*:*:*:*:*:*
Summary For Realtek AmebaD devices, a heap-based buffer overflow was discovered in Ameba-AIoT ameba-arduino-d before version 3.1.9 and ameba-rtos-d before commit c2bfd8216a1cbc19ad2ab5f48f372ecea756d67a on 2025/07/03. In the WLAN driver defragment function, lack of validation of the size of fragmented Wi-Fi frames may lead to a heap-based buffer overflow. Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

18 Jul 2025, 17:55

Type Values Removed Values Added
CPE cpe:2.3:a:realtek:ameba-rtos-d:*:*:*:*:*:*:*:*
cpe:2.3:a:realtek:ameba_arduino_sdk:*:*:*:*:*:*:*:*
First Time Realtek ameba-rtos-d
Realtek
Realtek ameba Arduino Sdk
References () https://github.com/Ameba-AIoT/ameba-arduino-d/pull/281 - () https://github.com/Ameba-AIoT/ameba-arduino-d/pull/281 - Patch
References () https://www.amebaiot.com/en/security-bulletin-cve-2025-49604/ - () https://www.amebaiot.com/en/security-bulletin-cve-2025-49604/ - Broken Link
References () https://github.com/Ameba-AIoT/ameba-arduino-d/releases/tag/V3.1.9 - () https://github.com/Ameba-AIoT/ameba-arduino-d/releases/tag/V3.1.9 - Release Notes

09 Jul 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-09 16:15

Updated : 2025-07-22 15:15


NVD link : CVE-2025-49604

Mitre link : CVE-2025-49604


JSON object : View

Products Affected

No product.

CWE

No CWE.