Vulnerability Description
A vulnerability was found in PX4-Autopilot 1.12.3. It has been classified as problematic. This affects the function MavlinkReceiver::handle_message_trajectory_representation_waypoints of the file mavlink_receiver.cpp of the component TRAJECTORY_REPRESENTATION_WAYPOINTS Message Handler. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://github.com/PX4/PX4-Autopilot/issues/24915
- https://github.com/PX4/PX4-Autopilot/issues/24915#issue-3091040552
- https://vuldb.com/?ctiid.311127
- https://vuldb.com/?id.311127
- https://vuldb.com/?submit.584889
FAQ
What is CVE-2025-5640?
CVE-2025-5640 is a vulnerability with a CVSS score of 3.3 (LOW). A vulnerability was found in PX4-Autopilot 1.12.3. It has been classified as problematic. This affects the function MavlinkReceiver::handle_message_trajectory_representation_waypoints of the file mavl...
How severe is CVE-2025-5640?
CVE-2025-5640 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-5640?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.