PT-2025-3993 · Unknown · Routinator

Haya Schulmann

+1

·

Published

2025-01-22

·

Updated

2025-01-22

·

CVE-2025-0638

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Routinator (affected versions not specified)
Description The issue arises from the initial code parsing the manifest not checking the content of file names, while later code assumes this check has been performed. When encountering illegal characters, the system panics, resulting in a crash of Routinator. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-0638

Affected Products

Routinator