Data Injection Vulnerability in BIND Software by ISC
CVE-2025-40778

8.6HIGH

Key Information:

Vendor

Isc

Status
Vendor
CVE Published:
22 October 2025

Badges

👾 Exploit Exists

What is CVE-2025-40778?

This vulnerability in BIND software allows attackers to inject malicious data into the cache due to overly lenient acceptance of records from responses. This flaw affects multiple versions of BIND 9, posing a risk of cache poisoning, which could potentially lead to compromised network integrity and confidentiality.

Affected Version(s)

BIND 9 9.11.0 <= 9.16.50

BIND 9 9.18.0 <= 9.18.39

BIND 9 9.20.0 <= 9.20.13

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

ISC would like to thank Yuxiao Wu, Yunyi Zhang, Baojun Liu, and Haixin Duan from Tsinghua University for bringing this vulnerability to our attention.
.
CVE-2025-40778 : Data Injection Vulnerability in BIND Software by ISC