{"id":"CVE-2025-34458","title":"wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 3658a87, contain a reachable assertion vulnerability in the APRS MIC-E decoder function aprs_mic_e() located in src/decode_aprs.c","summary":"wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 3658a87, contain a reachable assertion vulnerability in the APRS MIC-E decoder function aprs_mic_e() located in src/decode_aprs.c. When processing a specially …","severity":"none","cwe":["CWE-617"],"published":"2025-12-22","updated":"2026-09-28","sourceUpdated":"2026-09-28T10:10:00.473","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-34458","references":[{"url":"https://github.com/marlinkcyber/advisories/blob/main/advisories/MCSAID-2025-010-direwolf-stack-buffer-overflow-kiss-frame.md","label":"disclosure@vulncheck.com"},{"url":"https://github.com/wb2osz/direwolf/commit/3658a87","label":"disclosure@vulncheck.com"},{"url":"https://github.com/wb2osz/direwolf/issues/618","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/wb2osz-direwolf-reachable-assertion-dos","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"epss":0.00461,"epssPercentile":0.37445,"ingestedAt":"2026-09-28T11:08:06.666Z","slug":"CVE-2025-34458","body":"## Overview\n\nwb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 3658a87, contain a reachable assertion vulnerability in the APRS MIC-E decoder function aprs_mic_e() located in src/decode_aprs.c. When processing a specially crafted AX.25 frame containing a MIC-E message with an empty or truncated comment field, the application triggers an unhandled assertion checking for a non-empty comment. This assertion failure causes immediate process termination, allowing a remote, unauthenticated attacker to cause a denial of service by sending malformed APRS traffic.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}