Critical severity9.8OSV Advisory· Published Dec 9, 2025· Updated Jul 5, 2026
CVE-2025-65882
CVE-2025-65882
Description
An issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade-helper/src/tools/sysupgrade.c in function create_xor_ipad_opad allowing attackers to potentially write arbitrary files or execute arbitrary commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4v0.1, v0.10, v0.18, …+ 1 more
- (no CPE)range: v0.1, v0.10, v0.18, …
- (no CPE)range: <=0.64
- cpe:2.3:a:openmptcprouter:openmptcprouter:*:*:*:*:*:*:*:*Range: <=0.64
- Range: <=0.64
Patches
Vulnerability mechanics
References
2- github.com/Ysurac/openmptcprouter/commit/09393d1c41a227bea7d5b85c0a06221b1302b25fnvdPatch
- gist.github.com/AradCohen/939ee50d60c4d2bd555a364615a5ab9cnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.