Tunneling Vulnerability in Networking Products Exposing Security Flaws
CVE-2025-23018
5.4MEDIUM
What is CVE-2025-23018?
The vulnerability arises due to the lack of validation within IPv4-in-IPv6 and IPv6-in-IPv6 tunneling protocols, as specified in RFC 2473. This oversight enables an attacker to forge network packets and reroute arbitrary traffic through vulnerable network interfaces. The potential for abuse is significant, as attackers can exploit this issue to create unauthorized network pathways, compromising the integrity and confidentiality of transmitted data.
Affected Version(s)
IPv6 6