VYPR
High severity7.8NVD Advisory· Published May 28, 2025· Updated Jun 17, 2026

CVE-2025-32801

CVE-2025-32801

Description

Kea configuration and API directives can be used to load a malicious hook library. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecure paths. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

9

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.