CVE-2025-51677
CRITICALCVSS 9.1/10EPSS 0.43%
Last modified
CVE-2025-51677 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or1200 cpu output port can lead to unexpected behavior.. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or1200 cpu output port can lead to unexpected behavior.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | — | n/a |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-51677?
An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or1200 cpu output port can lead to unexpected behavior.
How severe is CVE-2025-51677?
CVE-2025-51677 has a CVSS score of 9.1/10 (CRITICAL severity). The EPSS model estimates a 0.43% probability of exploitation in the next 30 days.
How do I fix CVE-2025-51677?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-51662A stored cross-site scripting (XSS) vulnerability is found i…5.4
- CVE-2025-51663A vulnerability found in IPRateLimit implementation of FileC…7.5
- CVE-2025-51667An issue was discovered in simple-admin-core v1.2.0 thru v1.…7
- CVE-2025-5167A vulnerability was found in Open Asset Import Library Assim…5.5
- CVE-2025-51671A SQL injection vulnerability was discovered in the PHPGuruk…5.4
- CVE-2025-51672A time-based blind SQL injection vulnerability was identifie…8
- CVE-2025-51678An issue was discovered in RISC-V PicoRV32 commit 87c89a. A …7.5
- CVE-2025-5168A vulnerability was found in Open Asset Import Library Assim…5.5
- CVE-2025-51682mJobtime 15.7.2 handles authorization on the client side, wh…9.8
- CVE-2025-51683A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7…9.8
- CVE-2025-51684CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Script…6.1
- CVE-2025-5169A vulnerability classified as problematic has been found in …5.5
Are you affected by CVE-2025-51677?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
