diff --git a/advisories/unreviewed/2025/06/GHSA-4xh2-4xwh-6pgr/GHSA-4xh2-4xwh-6pgr.json b/advisories/unreviewed/2025/06/GHSA-4xh2-4xwh-6pgr/GHSA-4xh2-4xwh-6pgr.json new file mode 100644 index 00000000000..3dce0259f67 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-4xh2-4xwh-6pgr/GHSA-4xh2-4xwh-6pgr.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xh2-4xwh-6pgr", + "modified": "2025-06-09T09:31:04Z", + "published": "2025-06-09T09:31:03Z", + "aliases": [ + "CVE-2025-5865" + ], + "details": "A vulnerability was found in RT-Thread 5.1.0. It has been rated as critical. Affected by this issue is the function sys_select of the file rt-thread/components/lwp/lwp_syscall.c of the component Parameter Handler. The manipulation of the argument timeout leads to memory corruption. The vendor explains, that \"[t]he timeout parameter should be checked to check if it can be accessed correctly in kernel mode and used temporarily in kernel memory.\"", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5865" + }, + { + "type": "WEB", + "url": "https://github.com/RT-Thread/rt-thread/issues/10298" + }, + { + "type": "WEB", + "url": "https://github.com/RT-Thread/rt-thread/issues/10298#issuecomment-2894952150" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311624" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311624" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584124" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T07:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-5cq9-g28q-5w6r/GHSA-5cq9-g28q-5w6r.json b/advisories/unreviewed/2025/06/GHSA-5cq9-g28q-5w6r/GHSA-5cq9-g28q-5w6r.json new file mode 100644 index 00000000000..01c4100a5c2 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-5cq9-g28q-5w6r/GHSA-5cq9-g28q-5w6r.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cq9-g28q-5w6r", + "modified": "2025-06-09T09:31:04Z", + "published": "2025-06-09T09:31:04Z", + "aliases": [ + "CVE-2025-5868" + ], + "details": "A vulnerability, which was classified as critical, has been found in RT-Thread 5.1.0. This issue affects the function sys_thread_sigprocmask of the file rt-thread/components/lwp/lwp_syscall.c. The manipulation of the argument how leads to improper validation of array index.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5868" + }, + { + "type": "WEB", + "url": "https://github.com/RT-Thread/rt-thread/issues/10303" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311627" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311627" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584130" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T08:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8frm-3xf6-7ff2/GHSA-8frm-3xf6-7ff2.json b/advisories/unreviewed/2025/06/GHSA-8frm-3xf6-7ff2/GHSA-8frm-3xf6-7ff2.json new file mode 100644 index 00000000000..acea913eaa8 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8frm-3xf6-7ff2/GHSA-8frm-3xf6-7ff2.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8frm-3xf6-7ff2", + "modified": "2025-06-09T09:31:04Z", + "published": "2025-06-09T09:31:04Z", + "aliases": [ + "CVE-2025-5870" + ], + "details": "A vulnerability has been found in TRENDnet TV-IP121W 1.1.1 Build 36 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/setup.cgi of the component Web Interface. The manipulation leads to improper authentication. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5870" + }, + { + "type": "WEB", + "url": "https://github.com/zeke2997/CVE_request_TRENDnet" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311629" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311629" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.585435" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T09:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-hh8x-xr4m-qghx/GHSA-hh8x-xr4m-qghx.json b/advisories/unreviewed/2025/06/GHSA-hh8x-xr4m-qghx/GHSA-hh8x-xr4m-qghx.json new file mode 100644 index 00000000000..66325709d39 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-hh8x-xr4m-qghx/GHSA-hh8x-xr4m-qghx.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh8x-xr4m-qghx", + "modified": "2025-06-09T09:31:04Z", + "published": "2025-06-09T09:31:04Z", + "aliases": [ + "CVE-2025-5894" + ], + "details": "Smart Parking Management System from Honding Technology has a Missing Authorization vulnerability, allowing remote attackers with regular privileges to access a specific functionality to create administrator accounts, and subsequently log into the system using those accounts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5894" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-10171-44c0a-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-10170-e2435-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T08:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-mq4q-q9rw-jvph/GHSA-mq4q-q9rw-jvph.json b/advisories/unreviewed/2025/06/GHSA-mq4q-q9rw-jvph/GHSA-mq4q-q9rw-jvph.json new file mode 100644 index 00000000000..1cdae5d1d6c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-mq4q-q9rw-jvph/GHSA-mq4q-q9rw-jvph.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq4q-q9rw-jvph", + "modified": "2025-06-09T09:31:04Z", + "published": "2025-06-09T09:31:04Z", + "aliases": [ + "CVE-2025-5867" + ], + "details": "A vulnerability classified as critical was found in RT-Thread 5.1.0. This vulnerability affects the function csys_sendto of the file rt-thread/components/lwp/lwp_syscall.c. The manipulation of the argument to leads to null pointer dereference.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5867" + }, + { + "type": "WEB", + "url": "https://github.com/RT-Thread/rt-thread/issues/10299" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311626" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311626" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584129" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T08:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-vwm9-6f8w-5whc/GHSA-vwm9-6f8w-5whc.json b/advisories/unreviewed/2025/06/GHSA-vwm9-6f8w-5whc/GHSA-vwm9-6f8w-5whc.json new file mode 100644 index 00000000000..31866d626a5 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-vwm9-6f8w-5whc/GHSA-vwm9-6f8w-5whc.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwm9-6f8w-5whc", + "modified": "2025-06-09T09:31:04Z", + "published": "2025-06-09T09:31:04Z", + "aliases": [ + "CVE-2025-5893" + ], + "details": "Smart Parking Management System from Honding Technology has an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to access a specific page and obtain plaintext administrator credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5893" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-10169-651d6-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-10167-39c6d-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-256" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T07:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-xr69-f8gw-5vr7/GHSA-xr69-f8gw-5vr7.json b/advisories/unreviewed/2025/06/GHSA-xr69-f8gw-5vr7/GHSA-xr69-f8gw-5vr7.json new file mode 100644 index 00000000000..54d3bf8e17e --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-xr69-f8gw-5vr7/GHSA-xr69-f8gw-5vr7.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr69-f8gw-5vr7", + "modified": "2025-06-09T09:31:04Z", + "published": "2025-06-09T09:31:04Z", + "aliases": [ + "CVE-2025-5869" + ], + "details": "A vulnerability, which was classified as critical, was found in RT-Thread 5.1.0. Affected is the function sys_recvfrom of the file rt-thread/components/lwp/lwp_syscall.c. The manipulation of the argument from leads to memory corruption.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5869" + }, + { + "type": "WEB", + "url": "https://github.com/RT-Thread/rt-thread/issues/10304" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311628" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311628" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584135" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T09:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-xxqp-4rfr-9px7/GHSA-xxqp-4rfr-9px7.json b/advisories/unreviewed/2025/06/GHSA-xxqp-4rfr-9px7/GHSA-xxqp-4rfr-9px7.json new file mode 100644 index 00000000000..bb7de1c24cf --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-xxqp-4rfr-9px7/GHSA-xxqp-4rfr-9px7.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxqp-4rfr-9px7", + "modified": "2025-06-09T09:31:04Z", + "published": "2025-06-09T09:31:04Z", + "aliases": [ + "CVE-2025-5866" + ], + "details": "A vulnerability classified as critical has been found in RT-Thread 5.1.0. This affects the function sys_sigprocmask of the file rt-thread/components/lwp/lwp_syscall.c. The manipulation of the argument how leads to improper validation of array index.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5866" + }, + { + "type": "WEB", + "url": "https://github.com/RT-Thread/rt-thread/issues/10300" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311625" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311625" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584127" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T07:15:22Z" + } +} \ No newline at end of file