Multicast Packet Handling Flaw in Cisco IOS XR Software for ASR 9000 and 9900 Series Routers
CVE-2025-20146
What is CVE-2025-20146?
A vulnerability in the Layer 3 multicast feature of Cisco IOS XR Software can be exploited by remote attackers to disrupt service on Cisco ASR 9000 and ASR 9900 Series Routers. The flaw arises from improper handling of malformed IPv4 multicast packets, which can lead to a line card reset, resulting in a denial of service condition. Attackers may send specifically crafted multicast traffic that triggers exceptions or a hard reset in affected line cards, causing temporary service interruptions as traffic is lost during reloads.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco IOS XR Software 7.11.1
Cisco IOS XR Software 7.9.21
Cisco IOS XR Software 7.10.2
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved