CVE-2025-9019 describes a heap-based buffer overflow vulnerability in tcpreplay version 4.5.1, specifically within the mask_cidr6 function of the cidr.c file in the tcpprep component. This vulnerability carries a MEDIUM severity CVSS score of 5.9, indicating a remote attack vector with high complexity, but potentially leading to high availability impact. While public exploit disclosure exists, the maintainer states it was fixed in version 4.5.2, and there is no evidence of active exploitation, Metasploit modules, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.5.1CPE matchmatch criteria | cpe:2.3:a:broadcom:tcpreplay:4.5.1:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.