Junglewise Threat Intelligence

CVE-2025-10450: RTI Connext Professional network traffic sniffing via unencrypted communication

CVE-2025-10450 · Severity: high · CVSS 7.5 · Published 2025-12-16

Technologies: Rti Connext Professional. Vendors: Rti.

Executive brief

RTI Connext Professional is a middleware platform used for real-time distributed system communication. This vulnerability allows an attacker on the network to intercept and read unencrypted traffic, exposing sensitive data exchanged between Connext-based applications without requiring authentication or special privileges.

Technical details

The vulnerability is a failure to encrypt network communication in the Connext Professional Core Libraries, allowing network sniffing of unprotected traffic. The issue affects versions 7.4.0 through 7.6.x and 7.2.0 through 7.3.0. An attacker positioned on the network (adjacent or same subnet) can passively capture and read Connext communication traffic. No authentication or user interaction is required to exploit this vulnerability; only network access is needed. Patches are available for supported LTS versions through RTI's standard patching process.

Affected products

  • RTI Connext Professional 7.4.0 to 7.6.x, 7.2.0 to 7.3.0

Timeline

  • 2025-12-16: disclosed
  • 2025-12-16: patched: Patches available for 7.7.0 and 7.3.1+

References

Related threats