← Vulnerability feed

Vulnerability record · CVE-2025-11617 · published 10 October 2025

CVE-2025-11617: Amazon freertos-plus-tcp vulnerability

Amazon · Freertos Plus Tcp

A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when receiving a IPv6 packet with incorrect payload lengths in the packet header. This issue only affects applications using IPv6. We recommend users upgrade to the latest version and ensure any forked or derivative code is patched to incorporate the new fixes.

5.3 CVSS 4.0 Medium EPSS 0.31% · top 79.1% CWE-126 · CWE-126
5.3CVSS 4.0 base score
0.31%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when receiving a IPv6 packet with incorrect payload lengths in the packet header. This issue only affects applications using IPv6. We recommend users upgrade to the latest version and ensure any forked or derivative code is patched to incorporate the new fixes.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-11617 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2024-38373Amazon freertos-plus-tcp out-of-bounds read vulnerabilityFreeRTOS-Plus-TCP is a lightweight TCP/IP stack for FreeRTOS. FreeRTOS-Plus-TCP versions 4.0.0 through 4.1.0 contain a buffer over-read issue in the …EPSS 0.62%7.2CVE-2026-7424Amazon freertos-plus-tcp vulnerabilityInteger underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the devic…EPSS 0.37%7.1CVE-2026-7422Amazon freertos-plus-tcp authentication bypass by spoofing vulnerabilityInsufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size…EPSS 0.29%6.1CVE-2026-7426Amazon freertos-plus-tcp out-of-bounds write vulnerabilityInsufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an ad…EPSS 0.40%6.0CVE-2026-7425Amazon freertos-plus-tcp out-of-bounds read vulnerabilityInsufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent networ…EPSS 0.38%6.0CVE-2026-7423Amazon freertos-plus-tcp vulnerabilityInteger underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network user to cause a…EPSS 0.36%5.3CVE-2025-11616Amazon freertos-plus-tcp vulnerabilityA missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can lead to an out-of-bounds read when receiving ICMPv6 packets of ce…EPSS 0.31%5.3CVE-2025-11618Amazon freertos-plus-tcp null pointer dereference vulnerabilityA missing validation check in FreeRTOS-Plus-TCP's UDP/IPv6 packet processing code can lead to an invalid pointer dereference when receiving a UDP/IPv…EPSS 0.34%

Source: NIST National Vulnerability Database (record CVE-2025-11617), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.