CVE-2025-25373: Nasa Core Flight System

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The Memory Management Module of NASA cFS (Core Flight System) Aquila has insecure permissions, which can be exploited to gain an RCE on the platform.

Affected products

  • Nasa Core Flight System: version 6.7.0 only

Published 2025-03-25. Last modified 2026-06-17.