CVE-2025-62525 is a critical vulnerability in OpenWrt Project versions prior to 24.10.4, specifically impacting devices with Lantiq/Intel/MaxLinear xrx200, danube, and amazon SoCs operating in DSL PTM mode. This flaw allows local users to read and write arbitrary kernel memory through the ltq-ptm driver's ioctls. With a CVSS score of 8.8 (High), it presents a significant risk, enabling attackers to escape sandboxed environments and achieve full compromise of the affected system. While there are no known active exploits, public exploit code, or significant community discussion, the absence of workarounds necessitates immediate patching to version 24.10.4 for vulnerable deployments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 24.10.4CPE matchmatch criteria | cpe:2.3:o:openwrt:openwrt:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.