Impact
Qt for MCUs has a text rendering flaw in which a <img> tag that contains an attribute with an empty value causes the internal parser to report an error and the default error handler to halt the device. The flaw is an example of improper handling of malformed input (CWE‑230) that leads to denial of service. An attacker who can provide styled text to the device, such as through a GUI or an API, can trigger the halt, disrupting availability of the affected firmware.
Affected Systems
The vulnerability affects all versions of Qt for MCUs that include the Text element used for styled text rendering. No specific version range is listed, so the risk applies broadly to any installation of Qt for MCUs that has not applied a vendor fix.
Risk and Exploitability
The CVSS score of 6.6 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited current exploitation activity. However, because the flaw can be triggered by user‑supplied styled text, the likely attack vector is any user or remote interface that allows styled text input. If an attacker can supply malformed <img> tags, the device will halt, leading to a denial of service. The lack of a pre‑check for empty attribute values and the default error handler that halts the system make the flaw straightforward to exploit once the input vector is available.
OpenCVE Enrichment