VYPR
Medium severity5.4NVD Advisory· Published Jan 14, 2025· Updated Jun 17, 2026

CVE-2025-23018

CVE-2025-23018

Description

IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a network packet, allowing an attacker to spoof and route arbitrary traffic via an exposed network interface. This is a similar issue to CVE-2020-10136.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Ietf/Ipv62 versions
    cpe:2.3:a:ietf:ipv6:-:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ietf:ipv6:-:*:*:*:*:*:*:*
    • (no CPE)range: 6
  • Ietf/RFC 2473llm-create

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.