PT-2026-28761 · Frrouting · Frr

Rensiru

·

Published

2026-03-30

·

Updated

2026-03-30

·

CVE-2026-5107

CVSS v2.0

3.6

Low

AV:N/AC:H/Au:S/C:N/I:P/A:P
A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process type2 route of the file bgpd/bgp evpn.c of the component EVPN Type-2 Route Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is reported as difficult. The identifier of the patch is 7676cad65114aa23adde583d91d9d29e2debd045. To fix this issue, it is recommended to deploy a patch.

Fix

Improper Access Control

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2026-5107

Affected Products

Frr