CVE-2025-32801 describes a critical vulnerability in Kea versions 2.4.0-2.4.1, 2.6.0-2.6.2, and 2.7.0-2.7.8, allowing authenticated local attackers to load malicious hook libraries via Kea configuration or API directives. With a CVSS score of 7.8 (HIGH), this flaw permits high impact to confidentiality, integrity, and availability, particularly as Kea often runs as root with unsecured API endpoints. Despite its severity, there is currently no public exploit code, active exploitation, or significant community discussion, as indicated by its low EPSS score and lack of media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.4.0, <= 2.4.1CPE match | cpe:2.3:a:isc:kea:*:*:*:*:*:*:*:* | ||
>= 2.6.0, <= 2.6.2CPE match | cpe:2.3:a:isc:kea:*:*:*:*:*:*:*:* | ||
>= 2.7.0, <= 2.7.8CPE match | cpe:2.3:a:isc:kea:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.