Buffer Overflow Vulnerability in Net-SNMP SNMP Application Library
CVE-2025-68615

9.8CRITICAL

Key Information:

Vendor

Net-snmp

Status
Vendor
CVE Published:
22 December 2025

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸฃ EPSS 42%๐Ÿ“ฐ News Worthy

What is CVE-2025-68615?

CVE-2025-68615 is a buffer overflow vulnerability found in the Net-SNMP SNMP application library, which consists of tools and a daemon for managing network devices using the Simple Network Management Protocol (SNMP). This vulnerability exists in versions before 5.9.5 and 5.10.pre2 of the library, where a specially crafted packet sent to the net-snmp snmptrapd daemon can lead to a buffer overflow condition. Should this vulnerability be exploited, the daemon may crash, which could disrupt network management functions that rely on SNMP. Given that Net-SNMP is widely used in various network management systems, its compromise could hinder organizational operations and expose sensitive information.

Potential impact of CVE-2025-68615

  1. Service Disruption: The buffer overflow can cause the SNMP daemon to crash, which can result in the disruption of network monitoring and management capabilities, directly impacting the integrity and availability of network services.

  2. Security Risks: If exploited, this vulnerability may allow attackers to leverage the crash for further intrusion attempts, potentially leading to unauthorized access to network devices and sensitive data being exposed.

  3. Operational Overhead: Organizations may incur increased costs and resource usage due to the need for emergency patching, system recovery, and increased monitoring to ensure their environments remain secure after such an exploit.

Affected Version(s)

net-snmp < 5.9.5 < 5.9.5

net-snmp >= 5.10.pre1, < 5.10.pre2 < 5.10.pre1, 5.10.pre2

News Articles

CVE-2025-68615: Critical Net-SNMP Snmptrapd Flaw

CVE-2025-68615 is a critical Net-SNMP snmptrapd vulnerability enabling buffer overflow, service crashes, and potential remote code execution.

References

EPSS Score

42% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • ๐Ÿ‘พ

    Exploit known to exist

  • ๐Ÿ“ฐ

    First article discovered by The Cyber Express

  • Vulnerability published

  • Vulnerability Reserved

.