CVE-2025-35003
Apache NuttX RTOS: NuttX Bluetooth Stack HCI and UART DoS/RCE Vulnerabilities.
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
Improper Restriction of Operations within the Bounds of a Memory Buffer and Stack-based Buffer Overflow vulnerabilities were discovered in Apache NuttX RTOS Bluetooth Stack (HCI and UART components) that may result in system crash, denial of service, or arbitrary code execution, after receiving maliciously crafted packets. NuttX's Bluetooth HCI/UART stack users are advised to upgrade to version 12.9.0, which fixes the identified implementation issues. This issue affects Apache NuttX: from 7.25 before 12.9.0.
| CWE | CWE-119 CWE-121 |
| Vendor | apache software foundation |
| Product | apache nuttx rtos |
| Published | May 26, 2025 |
| Last Updated | Feb 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache nuttx rtos
Be the first to know when new critical vulnerabilities affecting apache software foundation apache nuttx rtos are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Apache Software Foundation / Apache NuttX RTOS
7.25 < 12.9.0
References
Credits
๐ Chongqing Lei <[email protected]> ๐ Zhen Ling <[email protected]> Chongqing Lei <[email protected]> Tomek CEDRO <[email protected]>