# CVE-2026-6683

## Summary

- **CVE ID:** CVE-2026-6683
- **Severity:** MEDIUM
- **CVSS Score:** 4.6 (CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** CWE-369
- **Published:** Jul 1, 2026
- **Last Modified:** Jul 1, 2026

## Description

FatFs R0.16 and earlier contains a divide-by-zero in exFAT sync logic bug when crafted metadata causes n_fatent - 2 to be zero during write/sync operations. This maps to CWE-369 (Divide By Zero). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (4.6, Medium). Network-delivered update media can make this remote in some pipelines. The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Partial.

## Affected Products

- ChaN — FatFs (0)

## References

- [CNA](https://www.runzero.com/blog/fatfs-bugs/)
- [CNA](https://github.com/runZeroInc/vulns-2026-fatfs-chance)
- [CNA](https://elm-chan.org/fsw/ff/)
- [CNA](https://www.runzero.com/advisories/fatfs-exfat-divide-by-zero-cve-2026-6683)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.31%
- **EPSS Percentile:** 23.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._