PT-2025-27144 · Unknown · Net::Ip::Lpm
Published
2025-06-27
·
Updated
2025-06-27
·
CVE-2025-40910
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Net::IP::LPM version 1.10
Description:
The issue arises from the improper consideration of leading zero characters in IP CIDR address strings, potentially allowing attackers to bypass access control based on IP addresses. This confusion can affect users who intentionally use octal notation, as well as those who believe they are using decimal notation, due to the use of leading zeros to indicate octal numbers.
Recommendations:
For Net::IP::LPM version 1.10, consider updating to a version that properly handles leading zero characters in IP CIDR address strings to prevent potential access control bypass. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Net::Ip::Lpm