CVE-2025-61106 is a NULL pointer dereference vulnerability in FRRouting (FRR) versions 4.0 through 10.4.1, allowing attackers to cause a Denial of Service (DoS) via a crafted OSPF packet. This vulnerability carries a CVSS score of 7.5 (High), indicating it can be exploited remotely with low complexity and no user interaction, leading to high availability impact. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0, <= 10.4.1CPE matchmatch criteria | cpe:2.3:a:frrouting:frrouting:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
frr: NULL pointer dereference in show_vty_ext_pref_pref_sid() in ospf_ext.c
Oct 28, 2025FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
Oct 14, 2025