CVE-2025-2837

CVSS 3.0 Score 8.8 of 10 (high)

Details

Published Mar 26, 2025
Updated: Mar 27, 2025
CWE ID 121

Summary

CVE-2025-2837 is a remote code execution vulnerability affecting Silicon Labs Gecko OS. The flaw, named ZDI-CAN-23245, is a stack-based buffer overflow issue in the HTTP request handling process. Attackers can exploit this vulnerability without authentication, enabling them to execute arbitrary code on affected devices. The root cause is the lack of proper validation of user-supplied data lengths before copying it to a stack-buffer. This vulnerability poses a significant risk to network-adjacent systems running the Silicon Labs Gecko OS.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share