CVE-2025-48516General

MEDIUMCVSS 6.9 · MEDIUM

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Insecure default configuration state of DDR5 memory module by AGESA Bootloader Firmware could allow an attacker with local user privilege to abuse the unprotected PMIC interface to create a permanent denial of service condition or affect the integrity of the memory module.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-276

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • General: 5 classified signals
  • Peaked 2d ago at 3 mentions (2026-05-27); latest day: 1
  • 7 total mentions across 4 days

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-05-15: 1Mentions · 2026-05-27: 3Mentions · 2026-05-28: 2Mentions · 2026-05-30: 1Active Exploitation · 2026-05-28: 1Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-05-30: 105-1505-2705-2805-30
Signal classification3 categories
General
571.4%
Active Exploitation
114.3%
Patch
114.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-151
General1
2026-05-273
General3
2026-05-282
Active Exploitation1General1
2026-05-301
Patch1
Full discourse7 posts
  • ikjd_twi@ik_kato
    General

    ›CVE-2025-48516 現行世代まで含めてほぼ全ての世代のRyzen CPUで手立て無しかよ()

    Post summary

    The text notes that CVE-2025-48516 affects almost all Ryzen CPU generations with no available fix, providing no further technical or mitigation details.

    10010365
    389 followersView on X
  • kandorean@kandorean1
    General

    訂正 治せない→直せない とりあえず有識者の「CVE-2025-48516」解説待つかぁ…("No fix planned"並びすぎてよく分からない)

    Post summary

    The user notes that CVE-2025‑48516 is reportedly unfixed and is awaiting a detailed explanation from experts.

    00010321
    593 followersView on X
  • yocchicchi@six_one_sig
    Patch

    > DDR5メモリーモジュールに関する「CVE-2025-48516」は、…「修正の予定なし」 これ、geminiさんで確認したら、サーバー系には致命的な不具合だと思うのだが、なぜか扱いが小さい。 大炎上し、個人的にはリコールレベルだと思うのですが…。

    Post summary

    The tweet notes that CVE-2025‑48516 affects DDR5 modules, states that no patch is scheduled, and calls it potentially severe for servers, but lacks technical or exploit details.

    00000140
    118 followersView on X
  • 御坂すばる@subaru_misaka
    General

    CVE-2025-48516 この不具合って、つまりは放置😥

    Post summary

    The post simply references CVE-2025-48516 and notes the issue is left unresolved, providing no further technical or operational details.

    00000123
    690 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting AMD Ryzen 4000 Mobile Processors with Radeon Graphics and other products (CVE-2025-48516) https://vuldb.com/vuln/364139/cti

    Post summary

    The statement indicates that adversaries are actively targeting the CVE-2025-48516 vulnerability, but does not provide details on PoC, exploits, or fixes.

    0000082
    2.2K followersView on X
  • ユイチー@gerugo_4
    General

    >なお、DDR5メモリーモジュールに関する「CVE-2025-48516」は、対処にハードウェアの変更が必要とのことで、ほとんどの対象製品で「修正の予定なし」とされている。 ??????????????????????????(XファイルのBGM)

    Post summary

    The tweet merely announces that CVE-2025-48516 pertains to DDR5 memory modules and that most affected products have no fix planned, with no further technical or exploit information.

    00000298
    9 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-48516 Insecure DDR5 Memory Module Default Configuration in AGESA Bootloader Firmware https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-48516

    Post summary

    The post only references CVE-2025-48516 and a broad statement about insecure DDR5 default configuration in AGESA firmware, offering no concrete evidence of exploits, patches, or detailed technical data.

    000001.4K
    4.0K followersView on X

Explore more