VDB
CVE-2025-9688
CVE-2025-9688
PUBLISHED
CVSS 2.299999952316284 LOW
A security vulnerability has been detected in Mupen64Plus up to 2.6.0. The affected element is the function write_is_viewer of the file src/device/cart/is_viewer.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is described as difficult. The exploit has been disclosed publicly and may be used. The identifier of the patch is 3984137fc0c44110f1ef876adb008885b05a6e18. To fix this issue, it is recommended to deploy a patch.
EPSS 0.28% · 20.0th percentile
Risk Scores
CVSS 4.0
2.299999952316284
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
EPSS Score
0.28%
20.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | Mupen64Plus | 2.0, 2.1, 2.2 |
Timeline
- Aug 30, 2025 CVE Published
- Aug 31, 2025 EPSS Score
- Sep 2, 2025 CVE Updated
- Sep 8, 2025 EPSS Score
- Sep 16, 2025 EPSS Score
- Sep 23, 2025 EPSS Score
- Oct 1, 2025 EPSS Score
- Oct 9, 2025 EPSS Score
- Oct 17, 2025 EPSS Score
- Oct 24, 2025 EPSS Score
- Nov 1, 2025 EPSS Score
- Nov 9, 2025 EPSS Score
References
- https://github.com/mupen64plus/mupen64plus-core/commit/3984137fc0c44110f1ef876adb008885b05a6e18 fix
- VDB-321900 | Mupen64Plus is_viewer.c write_is_viewer integer overflow vdb
- VDB-321900 | CTI Indicators (IOB, IOC, IOA) url
- Submit #638592 | mupen64plus.org mupen64plus <= 2.6.0 Integer Overflow to Buffer Overflow third-party-advisory
- https://github.com/Giles-one/mupen64plusEscape/tree/main/BUG10 exploit