CVE-2025-2837
CVSS 3.0 Score 8.8 of 10 (high)
Details
Published Mar 26, 2025
Updated: Mar 27, 2025
CWE ID 121
Summary
CVE-2025-2837 is a remote code execution vulnerability affecting Silicon Labs Gecko OS. The flaw, named ZDI-CAN-23245, is a stack-based buffer overflow issue in the HTTP request handling process. Attackers can exploit this vulnerability without authentication, enabling them to execute arbitrary code on affected devices. The root cause is the lack of proper validation of user-supplied data lengths before copying it to a stack-buffer. This vulnerability poses a significant risk to network-adjacent systems running the Silicon Labs Gecko OS.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.