CVE-2024-45064: St X-Cube-Azrt-h7rs

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted set of network packets can lead to code execution. An attacker can send a sequence of requests to trigger this vulnerability.

Affected products

  • St X-Cube-Azrt-h7rs: version 1.0.0 only
  • St X-Cube-Azrtos-f4: version 1.1.0 only
  • St X-Cube-Azrtos-f7: version 1.1.0 only
  • St X-Cube-Azrtos-g0: version 1.1.0 only
  • St X-Cube-Azrtos-g4: version 2.0.0 only
  • St X-Cube-Azrtos-h7: version 3.3.0 only
  • St X-Cube-Azrtos-l4: version 2.0.0 only
  • St X-Cube-Azrtos-l5: version 2.0.0 only
  • St X-Cube-Azrtos-Wb: version 2.0.0 only
  • St X-Cube-Azrtos-Wl: version 2.0.0 only

Published 2025-04-02. Last modified 2026-06-17.