CVE-2025-5688 is a buffer overflow vulnerability that results in an out-of-bounds write when processing LLMNR or mDNS queries containing very long DNS names. Based on the provided information, the flaw is triggered during DNS name handling in code paths used for LLMNR or mDNS query processing. The issue only affects systems using Buffer Allocation Scheme 1 and only when LLMNR or mDNS is enabled. The vulnerability is therefore configuration-dependent and tied to malformed or oversized name input in local name-resolution traffic.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a small Python proof-of-concept exploit for CVE-2025-5688 affecting FreeRTOS-Plus-TCP <= 4.3.1 when LLMNR or mDNS is enabled (and Buffer Allocation Scheme 1 is used). The core script (FreeRTOS.py) crafts a DNS-like query with an overlong QNAME (8 maximum-length labels) and sends it via UDP multicast to either LLMNR (224.0.0.252:5355) or mDNS (224.0.0.251:5353). This is intended to trigger an out-of-bounds write in the target’s LLMNR/mDNS name parsing, commonly resulting in device crash/reboot/freeze; no shellcode, command execution, or reliability primitives are included. README.md provides background, affected versions/devices (e.g., Sonoff RF Bridge), expected symptoms, and references; it also notes the exploit requires the attacker to be on the same LAN and that RCE is only a possibility depending on memory layout. Notable minor inconsistency: README usage examples refer to exploit.py while the actual script filename is FreeRTOS.py.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.