An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The DNS response data length is not checked (it can be set to an arbitrary value from a packet). This may lead to successful Denial-of-Service, and possibly Remote Code Execution.
Conclusion & alert: CVE-2020-25108 is rated High Risk (78.8/100): CVSS Critical severity, with high exploitation likelihood (EPSS 52.26%, 99th percentile).Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +40.69% over the last day, indicating growing attacker interest.Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Exploit prediction scoring system (EPSS) score for CVE-2020-25108
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).