Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

RTI — Vulnerabilities & Security Advisories 44

Browse all 44 CVE security advisories affecting RTI. AI-powered Chinese analysis, POCs, and references for each vulnerability.

RTI, primarily known for its Real-Time Publish-Subscribe (DDS) middleware, facilitates critical data exchange in aerospace, defense, and industrial automation sectors. With twenty-five recorded Common Vulnerabilities and Exposures, the software has historically exhibited significant security flaws, predominantly involving remote code execution and cross-site scripting. These vulnerabilities often stem from insufficient input validation and improper access controls within the communication protocols. Notably, several incidents have highlighted risks related to privilege escalation, allowing unauthorized users to gain elevated system access. The complexity of DDS implementations frequently exacerbates these issues, as misconfigurations can expose sensitive operational data to external threats. While essential for real-time systems, the middleware’s security posture requires rigorous patching and strict network segmentation to mitigate the potential for exploitation in high-stakes environments.

Found 39 results / 44 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-18626 Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. — Connext Professional CWE-125 6.8 Medium 2026-09-22
CVE-2026-18462 Integer Overflow or Wraparound, Improper Access Control vulnerability in RTI Connext Professional (Core Libraries) allows Shared Resource Manipulation. — Connext Professional CWE-190 7.3 High 2026-09-22
CVE-2026-18461 Use of Externally-Controlled Format String vulnerability in RTI Connext Professional (Core Libraries) allows Format String Injection. — Connext Professional CWE-134 9.2 Critical 2026-09-22
CVE-2026-18459 Incorrect Calculation vulnerability in RTI Connext Professional (Core Libraries) allows Abuse Existing Functionality. — Connext Professional CWE-682 8.7 High 2026-09-22
CVE-2026-18460 Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. — Connext Professional CWE-193 6.9 Medium 2026-09-22
CVE-2026-18458 Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. — Connext Professional CWE-125 6.8 Medium 2026-09-22
CVE-2026-18457 Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. — Connext Professional CWE-122 8.3 High 2026-09-22
CVE-2026-11388 Double Free vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation. — Connext Professional CWE-415 6.9 Medium 2026-09-22
CVE-2026-11389 Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. — Connext Professional CWE-125 6.8 Medium 2026-09-22
CVE-2026-8849 Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation. — Connext Professional CWE-416 7.7 High 2026-09-22
CVE-2026-7866 Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. — Connext Professional CWE-121 9.3 Critical 2026-09-22
CVE-2026-2674 Out-of-bounds Write vulnerability in RTI Connext Professional (Queueing Service,Core Libraries,Persistence Service) allows Overflow Buffers. — Connext Professional CWE-787 4.8 Medium 2026-06-17
CVE-2026-30799 Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Identity Spoofing. — Connext Professional CWE-306 6.1 Medium 2026-06-17
CVE-2026-7300 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Web Integration Service) allows Filter Failure through Buffer Overflow. — Connext Professional CWE-120 8.8 High 2026-06-17
CVE-2026-3894 Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. — Connext Professional CWE-125 8.2 High 2026-06-17
CVE-2026-2675 Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake the Source of Data. — Connext Professional CWE-306 6.0 Medium 2026-06-17
CVE-2026-2467 Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags. — Connext Professional CWE-122 8.2 High 2026-06-17
CVE-2025-14543 Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking. — Connext Professional CWE-611 6.9 Medium 2026-04-30
CVE-2026-4374 Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Recording Service,Routing Service,Queueing Service,Cloud Discovery Service,Observability Collector) allows Serialized Data External Linking, Data Serializat... — Connext Professional CWE-611 7.0 High 2026-04-01
CVE-2026-2394 Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. — Connext Professional CWE-126 4.8 Medium 2026-04-01
CVE-2025-10450 Exposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Professional (Core Libraries) allows Sniffing Network Traffic. — Connext Professional CWE-359 6.1 Medium 2025-12-16
CVE-2025-8410 Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation. — Connext Professional CWE-416 5.8 Medium 2025-09-23
CVE-2025-4993 Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation. — Connext Professional CWE-822 8.3 High 2025-09-23
CVE-2025-4582 Buffer Over-read, Off-by-one Error vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation, Overread Buffers. — Connext Professional CWE-126 4.8 Medium 2025-09-23
CVE-2025-1255 Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation. — Connext Professional CWE-822 8.3 High 2025-09-23
CVE-2025-1254 Out-of-bounds Read, Out-of-bounds Write vulnerability in RTI Connext Professional (Recording Service) allows Overflow Buffers, Overread Buffers. — Connext Professional CWE-125 7.3 High 2025-05-08
CVE-2025-1253 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags. — Connext Professional CWE-120 6.9 Medium 2025-05-08
CVE-2025-1252 Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags. — Connext Professional CWE-122 6.9 Medium 2025-05-08
CVE-2024-52066 Potential stack corruption in Routing Service when using a malicious XML configuration document — Connext Professional CWE-120 9.1 - 2024-12-13
CVE-2024-52065 Potential stack buffer write overflow in Persistence Service while parsing malicious environment variable on non-Windows systems — Connext Professional CWE-120 8.4 - 2024-12-13

This page lists every published CVE security advisory associated with RTI. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.