External risk intelligence

AIS-catcher Heap Buffer Overflow Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-66216

AIS-catcher is a specialized tool for receiving and processing Automatic Identification System (AIS) radio signals. While it processes network data, it is typically used in local, dedicated radio receiving setups rather than as an internet-facing service, web application, or gateway, making public internet exposure uncommon in standard deployments.

Out-of-bounds Write

Aiscatcher Ais Catcher

before 0.64

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability was found in AIS-catcher, software used for receiving maritime Automatic Identification System (AIS) signals. This flaw could allow an attacker to inject malicious data, potentially impacting system integrity. While the vulnerability has been patched, confirming if this specific software is in use is the primary concern.

  • Software flaw allows data injection.
  • Affects maritime signal reception systems.
  • Confirm relevance and exposure of this tool.

Attack Path

How an attacker could exploit the issue

An attacker could target the AIS::Message class in AIS-catcher by sending specially crafted network data. This data could exploit a heap buffer overflow, allowing the attacker to overwrite memory and potentially achieve arbitrary code execution.

  • No specific entry conditions required.
  • Triggered by specially crafted network data.
  • Risk of arbitrary data overwrites.

Live Threat

Current exploitation, exposure, and threat context

The AIS-catcher application, when running a version prior to 0.64, could allow an attacker to overwrite approximately 1KB of data within a 128-byte buffer. This could impact the integrity of the application's internal processing when handling AIS messages.

  • Application memory integrity.
  • Overwriting data in a buffer.
  • Potential for unpredictable service behavior.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and platform teams are likely responsible for AIS-catcher, a multi-platform AIS receiver. The first practical step is to identify all AIS-catcher installations, determine their reachability and criticality, locate the accountable owner, and then plan remediation based on risk.

  • Identify AIS-catcher installations.
  • Verify network reachability and criticality.
  • Plan remediation with accountable owners.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is AIS-catcher?

AIS-catcher is a multi-platform software tool designed to receive and process Automatic Identification System (AIS) radio signals. It is primarily used by maritime enthusiasts and professionals to track ships and monitor vessel traffic data transmitted over radio frequencies.

What does the CVE-2025-66216 vulnerability mean?

This vulnerability is a heap buffer overflow, classified as CWE-787. It occurs in the AIS::Message class when the software improperly handles incoming data. Specifically, it allows an attacker to write roughly 1KB of arbitrary data into a small 128-byte memory buffer, which can cause the application to crash or behave unexpectedly.

How is this heap buffer overflow triggered?

The vulnerability is triggered by sending specially crafted network data to the AIS-catcher application. Because the flaw exists in the core message processing logic, no special user interaction or authentication is required to initiate the overwrite attempt.

Is my instance of AIS-catcher at risk?

Halo Surface Signal notes that AIS-catcher is typically used in local, dedicated radio setups rather than as an internet-facing service, making public internet exposure rare. However, if your instance is reachable via a network that allows external traffic, it could be a target. You should verify if your deployment is isolated from untrusted networks.

What should I do to address CVE-2025-66216?

First, conduct an inventory to identify all systems running AIS-catcher. Check the version number of each installation; any version prior to 0.64 is vulnerable. If you are using an older version, you must update to version 0.64 or later, as this release includes the necessary patch to fix the memory buffer issue.

References