CVE-2025-26500

CVSS 3.1 Score 4.6 of 10 (medium)

Details

Published Mar 21, 2025
CWE ID 400

Summary

CVE-2025-26500 is a critical vulnerability affecting Wind River Systems VxWorks 7, from versions 22.06 through 24.03. This issue involves uncontrolled resource consumption, allowing excessive allocation. A specifically crafted USB packet can trigger the system to become unavailable, potentially leading to denial-of-service conditions. Organizations using VxWorks 7 are urged to apply the necessary patches to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share