Description
AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, an integer underflow vulnerability exists in the MQTT parsing logic of AIS-catcher. This vulnerability allows an attacker to trigger a massive Heap Buffer Overflow by sending a malformed MQTT packet with a manipulated Topic Length field. This leads to an immediate Denial of Service (DoS) and, when used as a library, severe Memory Corruption that can be leveraged for Remote Code Execution (RCE). This issue has been patched in version 0.64.
INFO
Published Date :
2025-11-29T01:57:52.613Z
Last Modified :
2025-12-01T14:11:01.007Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2025-66217 vulnerability.
| Vendors | Products |
|---|---|
| Ais-catcher Project |
|
| Aiscatcher |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-66217.