CVE-2025-9019

3.1 LOW
Published: August 15, 2025 Modified: April 29, 2026
View on NVD

Description

A vulnerability has been found in tcpreplay 4.5.1. This vulnerability affects the function mask_cidr6 of the file cidr.c of the component tcpprep. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The researcher is able to reproduce this with the latest official release 4.5.1 and the current master branch. The code maintainer cannot reproduce this for 4.5.2-beta1. In his reply the maintainer explains that "[i]n that case, this is a duplicate that was fixed in 4.5.2."

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://github.com/appneta/tcpreplay/issues/958
Source: cna@vuldb.com
Exploit Issue Tracking Patch Vendor Advisory
https://github.com/appneta/tcpreplay/issues/958#issuecomment-3124876035
Source: cna@vuldb.com
Exploit Issue Tracking Patch Vendor Advisory
https://github.com/appneta/tcpreplay/issues/959
Source: cna@vuldb.com
Exploit Issue Tracking Vendor Advisory
https://vuldb.com/?ctiid.320080
Source: cna@vuldb.com
Permissions Required VDB Entry
https://vuldb.com/?id.320080
Source: cna@vuldb.com
Third Party Advisory VDB Entry
https://vuldb.com/?submit.623635
Source: cna@vuldb.com
Exploit Third Party Advisory VDB Entry
https://vuldb.com/?submit.623636
Source: cna@vuldb.com
Exploit Third Party Advisory VDB Entry
https://vuldb.com/?submit.623637
Source: cna@vuldb.com
Exploit Third Party Advisory VDB Entry
https://vuldb.com/?submit.623638
Source: cna@vuldb.com
Exploit Third Party Advisory VDB Entry
https://vuldb.com/?submit.623639
Source: cna@vuldb.com
Exploit Third Party Advisory VDB Entry
https://github.com/appneta/tcpreplay/issues/958
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Exploit Issue Tracking Patch Vendor Advisory
https://github.com/appneta/tcpreplay/issues/959
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Exploit Issue Tracking Vendor Advisory
https://vuldb.com/?submit.623639
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Exploit Third Party Advisory VDB Entry

14 reference(s) from NVD

Quick Stats

CVSS v3 Score
3.1 / 10.0
EPSS (Exploit Probability)
0.5%
66th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

broadcom