Denial of Service Vulnerability in FreeRTOS-Plus-TCP by Amazon Web Services
CVE-2026-7425
6MEDIUM
What is CVE-2026-7425?
A vulnerability exists in the IPv6 Router Advertisement parser of FreeRTOS-Plus-TCP prior to version 4.2.6 and 4.4.1. Due to insufficient option length validation, an adjacent network actor can exploit this weakness by sending a specially crafted Router Advertisement containing a truncated PREFIX_INFORMATION option, resulting in a device crash. Users are encouraged to upgrade to the latest versions to mitigate the risk of this vulnerability.
Affected Version(s)
FreeRTOS-Plus-TCP 4.0.0 < 4.2.6
FreeRTOS-Plus-TCP 4.3.0 < 4.4.1
FreeRTOS-Plus-TCP 4.2.6
