Impact
The CVE describes a stack-based buffer overflow in the CAN_Receive function of the SWM341_CSL library within RT‑Thread firmware. By sending a crafted CAN message on the local controller area network, an attacker can corrupt the stack, overwrite return addresses or local variables, and achieve arbitrary code execution or a system crash. This flaw corresponds to CWE‑119 and CWE‑121.
Affected Systems
All RT‑Thread firmware releases up to and including version 5.0.2 that include the SWM341_CSL library are affected. The vulnerability resides in the file bsp/synwit/libraries/SWM341_CSL/CMSIS/DeviceSupport/SWM341.h, which is compiled into devices that use the SWM341 CAN controller. Devices communicating over the local CAN interface are at risk.
Risk and Exploitability
The CVSS base score of 8.5 classifies the issue as high severity, and the EPSS score of less than 1 % indicates that large-scale exploitation is currently unlikely, although the public exploit has already been released. Because the flaw requires local access to the CAN interface, attackers must have physical or administrative proximity to the device. The vulnerability is not listed in the CISA KEV catalog, so no formal warning exists for these products.
OpenCVE Enrichment