CVE-2025-69217 is a high-severity vulnerability affecting coturn versions 4.6.2r5 through 4.7.0-r4, stemming from a weak pseudorandom number generator used for nonces and port randomization. An attacker can reconstruct the random number generator's state by sending approximately 50 unauthenticated allocation requests, allowing them to predict nonces and spoof IPs for authentication, even without receiving responses. This flaw also enables prediction of relay port randomization. The vulnerability has a CVSS score of 7.7 (High) due to its low attack complexity and potential for high impact on availability, though confidentiality and integrity are not directly affected. There is currently no public exploit code, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Coturn | Coturn | >= 4.6.2r5, <= 4.7.0-r4CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.