CVE-2025-25066

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Feb 3, 2025
CWE ID 121

Summary

CVE-2025-25066 is a newly discovered vulnerability affecting nDPI version 4.12 and below. This issue involves a stack-based buffer overflow in the ndpi_address_cache_restore function located in lib/ndpi_cache.c. An attacker could exploit this vulnerability by sending maliciously crafted network traffic to trigger the buffer overflow, potentially resulting in arbitrary code execution and subsequent system compromise. It is recommended that affected users upgrade to the latest version of nDPI to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share