PT-2025-51802 · Freebsd+2 · Freebsd+2
Kevin Day
·
Published
2025-12-16
·
Updated
2026-03-11
·
CVE-2025-14558
CVSS v2.0
8.3
High
| AV:A/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FreeBSD (affected versions not specified)
Description
A remote code execution issue exists in the IPv6 autoconfiguration handler in FreeBSD. The issue is present in the
rtsold background process and the rtsol utility. An attacker can achieve remote code execution with root privileges by sending a specially crafted IPv6 router advertisement packet. Router Advertisement (RA) messages used to exploit this issue are not routed and should be dropped by routers. To successfully exploit this, an attacker must be able to send a crafted packet from a system within the same network segment as the vulnerable host.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freebsd
Resolvconf
Rtsold