PT-2025-23035 · Unknown+1 · Net::Cidr::Set+2

Robert Rothenberg

·

Published

2025-05-27

·

Updated

2025-05-28

·

CVE-2025-40911

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Net::CIDR::Set versions 0.10 through 0.13
Description The issue arises from the improper handling of leading zero characters in IP CIDR address strings, potentially allowing attackers to bypass access control based on IP addresses. This is due to the interpretation of leading zeros as indicating octal numbers, which can cause confusion among users, whether they intend to use octal or decimal notation. The vulnerable code originates from Net::CIDR::Lite, which had a similar issue.
Recommendations For Net::CIDR::Set versions 0.10 through 0.13, consider updating to a version that properly handles leading zero characters in IP CIDR address strings to prevent potential access control bypass. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-40911

Affected Products

Debian
Net-Cidr-Lite
Net::Cidr::Set