CVE-2025-23018

IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a network packet, allowing an attacker to spoof and route arbitrary traffic via an exposed network interface. This is a similar issue to CVE-2020-10136.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ietf:ipv6:-:*:*:*:*:*:*:*

History

03 Nov 2025, 21:19

Type Values Removed Values Added
References
  • () https://www.kb.cert.org/vuls/id/199397 -

Information

Published : 2025-01-14 20:15

Updated : 2025-11-03 21:19


NVD link : CVE-2025-23018

Mitre link : CVE-2025-23018

CVE.ORG link : CVE-2025-23018


JSON object : View

Products Affected

ietf

  • ipv6
CWE
CWE-940

Improper Verification of Source of a Communication Channel

NVD-CWE-Other