CVE-2025-0870Active Exploitation(axiosys / bento4)

LOWCVSS 5.9 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for axiosys bento4 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is the function AP4_DataBuffer::GetData in the library Ap4DataBuffer.h. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-122CWE-787

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bento4

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
bento4

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-13: 1Active Exploitation · 2026-02-13: 102-13
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting Axiomatic Bento4 (CVE-2025-0870) https://vuldb.com/?ctiid.294056

    Post summary

    The post reports that offensive actors have identified and likely exploited CVE‑2025‑0870 in Axiomatic Bento4, but provides no PoC, exploit code, patch information, or technical details.

    0000053
    2.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appaxiosysbento4---

Explore more