Denial of Service Vulnerability in FreeRTOS-Plus-TCP by Amazon Web Services
CVE-2026-7425

6MEDIUM

Key Information:

Vendor

Aws

Vendor
CVE Published:
29 April 2026

What is CVE-2026-7425?

A vulnerability exists in the IPv6 Router Advertisement parser of FreeRTOS-Plus-TCP prior to version 4.2.6 and 4.4.1. Due to insufficient option length validation, an adjacent network actor can exploit this weakness by sending a specially crafted Router Advertisement containing a truncated PREFIX_INFORMATION option, resulting in a device crash. Users are encouraged to upgrade to the latest versions to mitigate the risk of this vulnerability.

Affected Version(s)

FreeRTOS-Plus-TCP 4.0.0 < 4.2.6

FreeRTOS-Plus-TCP 4.3.0 < 4.4.1

FreeRTOS-Plus-TCP 4.2.6

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.