← Vulnerability feed

Vulnerability record · CVE-2025-54126 · published 29 July 2025

CVE-2025-54126: Bytecodealliance webassembly micro runtime exposure of resource to wrong sphere vulnerability

Bytecodealliance · Webassembly Micro Runtime

The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WASI) and command line interface. In versions 2.4.0 and below, iwasm uses --addr-pool with an IPv4 address that lacks a subnet mask, allowing the system to accept all IP addresses. This can unintentionally expose the service to all incoming connections and bypass intended access restrictions. Services relying on --addr-pool for restricting access by IP may unintentionally become open to all external connections. This may lead to unauthorized access in production deployments, especially when users assume that specifying an IP without a subnet mask implies a default secure configuration. This is fixed in version 2.4.1.

6.9 CVSS 4.0 Medium EPSS 0.63% · top 51.7% CWE-668 · Exposure of resource to wrong sphere
6.9CVSS 4.0 base score
0.63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WASI) and command line interface. In versions 2.4.0 and below, iwasm uses --addr-pool with an IPv4 address that lacks a subnet mask, allowing the system to accept all IP addresses. This can unintentionally expose the service to all incoming connections and bypass intended access restrictions. Services relying on --addr-pool for restricting access by IP may unintentionally become open to all external connections. This may lead to unauthorized access in production deployments, especially when users assume that specifying an IP without a subnet mask implies a default secure configuration. This is fixed in version 2.4.1.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-54126 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2024-25431Bytecodealliance webassembly micro runtime out-of-bounds read vulnerabilityAn issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges via a cr…EPSS 0.63%7.5CVE-2024-27532Bytecodealliance webassembly micro runtime null pointer dereference vulnerabilitywasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_result_types.EPSS 0.51%7.5CVE-2024-34251Bytecodealliance webassembly micro runtime out-of-bounds read vulnerabilityAn out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a den…EPSS 0.76%7.5CVE-2023-48105Bytecodealliance webassembly micro runtime out-of-bounds write vulnerabilityAn heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of service v…EPSS 1.0%7.4CVE-2025-64713Bytecodealliance webassembly micro runtime memory buffer overflow vulnerabilityWebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, an out-of-bounds array access issue …EPSS 0.33%7.0CVE-2025-43853Bytecodealliance webassembly micro runtime vulnerabilityThe WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WAS…EPSS 0.28%6.2CVE-2024-34250Bytecodealliance webassembly micro runtime heap-based buffer overflow vulnerabilityA heap buffer overflow vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause at least a…EPSS 0.33%5.5CVE-2025-64704Bytecodealliance webassembly micro runtime vulnerabilityWebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, WAMR is susceptible to a segmentatio…EPSS 0.19%

Source: NIST National Vulnerability Database (record CVE-2025-54126), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.