CVE-2025-32802
Last modified
CVE-2025-32802 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecure paths. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecure paths. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-32802?
How severe is CVE-2025-32802?
How do I fix CVE-2025-32802?
Are you affected by CVE-2025-32802?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
