Local Memory Access Vulnerability in OpenWrt's Lantiq DSL Driver
CVE-2025-62525
What is CVE-2025-62525?
The OpenWrt Project's Lantiq DSL driver contains a vulnerability that allows local users to read and write arbitrary kernel memory. This issue impacts systems using the xrx200, danube, and amazon SoCs in PTM mode. When properly exploited, the vulnerability could enable an attacker to bypass sandboxes, potentially gaining unauthorized access to sensitive data or control over the device. This flaw is resolved in version 24.10.4 and affects devices relying on PTM, while those operating in ATM mode remain unaffected. Users are encouraged to upgrade to the latest version promptly.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
openwrt < 24.10.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
