Spoofing Vulnerability in PowerDNS Recursor by PowerDNS
CVE-2025-30192
What is CVE-2025-30192?
A vulnerability exists in PowerDNS Recursor that allows attackers to exploit ECS enabled requests, resulting in greater success rates for spoofing attempts compared to non-ECS enabled queries. The recent update implements multiple mitigations to counteract these spoofing attempts. These include enhanced validation of responses and the introduction of a configuration setting, outgoing.edns_subnet_harden, which strengthens the security of outgoing ECS queries, making it significantly harder for malicious actors to succeed.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Recursor 5.0.12
Recursor 5.0.12
Recursor 5.1.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
