← Vulnerability feed

Vulnerability record · CVE-2025-10450 · published 16 December 2025

CVE-2025-10450: Rti connext professional vulnerability

Rti · Connext Professional

Exposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Professional (Core Libraries) allows Sniffing Network Traffic. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.2.0 before 7.3.1.

8.3 CVSS 4.0 High EPSS 0.23% · top 87.6% CWE-359 · CWE-359
8.3CVSS 4.0 base score
0.23%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
22 Sep 2026Last modified by NVD

Description

Exposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Professional (Core Libraries) allows Sniffing Network Traffic. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.2.0 before 7.3.1.

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-10450 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-38435Rti connext professional vulnerabilityRTI Connext DDS Professional and Connext DDS Secure Versions 4.2x to 6.1.0 not correctly calculate the size when allocating the buffer, which may res…EPSS 1.4%9.2CVE-2026-3894Rti connext professional out-of-bounds read vulnerabilityOut-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from …EPSS 0.33%9.2CVE-2026-2467Rti connext professional heap-based buffer overflow vulnerabilityHeap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags. This issue affects Connext …EPSS 0.19%9.1CVE-2024-52057Rti connext professional sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RTI Connext Professional (Queuing Service) allo…EPSS 0.41%8.8CVE-2026-7300Rti connext professional classic buffer overflow vulnerabilityBuffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Web Integration Service) allows Fil…EPSS 0.42%8.8CVE-2025-14543Rti connext professional xml external entity (xxe) vulnerabilityImproper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Link…EPSS 0.21%8.8CVE-2026-4374Rti connext professional xml external entity (xxe) vulnerabilityImproper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Recording Service,Routing Service,Queueing Service,C…EPSS 0.39%8.8CVE-2021-38487Rti connext dds micro vulnerabilityRTI Connext Professional versions 4.1 to 6.1.0, and Connext Micro versions 2.4 and later are vulnerable when an attacker sends a specially crafted pa…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2025-10450), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.