CVE-2025-23018

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 940

Summary

CVE-2025-23018 is a vulnerability affecting IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473). This issue allows an attacker to spoof and route arbitrary traffic via an exposed network interface without proper verification of packet source. It is comparable to the CVE-2020-10136 vulnerability, which involved similar unvalidated packet source issues in IPv6 tunneling. This weakness can potentially lead to serious security implications, including data breaches and unauthorized access. Network administrators are advised to apply necessary patches or configurations to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share