CVE-2025-15150

EUVD-2025-205529
A vulnerability was found in PX4 PX4-Autopilot up to 1.16.0. Affected by this issue is the function MavlinkLogHandler::state_listing/MavlinkLogHandler::log_entry_from_id of the file src/modules/mavlink/mavlink_log_handler.cpp. The manipulation results in stack-based buffer overflow. The attack is only possible with local access. The patch is identified as 338595edd1d235efd885fd5e9f45e7f9dcf4013d. It is best practice to apply a patch to resolve this issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
VulDBCNA
5.3 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 13.09%
Affected Products (NVD)
VendorProductVersion
dronecodepx4_drone_autopilot
𝑥
≤ 1.16.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
px4autopilot
1.0
CNA
px4autopilot
1.1
CNA
px4autopilot
1.2
CNA
px4autopilot
1.3
CNA
px4autopilot
1.4
CNA
px4autopilot
1.5
CNA
px4autopilot
1.6
CNA
px4autopilot
1.7
CNA
px4autopilot
1.8
CNA
px4autopilot
1.9
CNA
px4autopilot
1.10
CNA
px4autopilot
1.11
CNA
px4autopilot
1.12
CNA
px4autopilot
1.13
CNA
px4autopilot
1.14
CNA
px4autopilot
1.15
CNA
px4autopilot
1.16.0
CNA