IP Address Handling Flaw in Net::CIDR::Set for Perl
CVE-2025-40911

6.5MEDIUM

Key Information:

Vendor

Rrwo

Vendor
CVE Published:
27 May 2025

What is CVE-2025-40911?

Net::CIDR::Set versions 0.10 through 0.13 for Perl have a vulnerability where leading zero characters in IP CIDR address strings are not properly handled. This flaw allows attackers to bypass access controls based on IP addresses, creating a potential security risk. Users may inadvertently input addresses in octal notation, leading to confusion between decimal and octal interpretations. This vulnerability leverages code from Net::CIDR::Lite, which has a related issue documented in previous security advisories.

Affected Version(s)

Net::CIDR::Set 0.10 <= 0.13

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.