CVE-2025-14558

The rtsol(8) and rtsold(8) programs do not validate the domain search list options provided in router advertisement messages; the option body is passed to resolvconf(8) unmodified. resolvconf(8) is a shell script which does not validate its input. A lack of quoting meant that shell commands pass as input to resolvconf(8) may be executed.
Configurations

No configuration.

History

09 Mar 2026, 14:16

Type Values Removed Values Added
References
  • () https://sploitus.com/exploit?id=MSF:EXPLOIT-FREEBSD-MISC-RTSOLD_DNSSL_CMDINJECT- -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

09 Mar 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-09 12:16

Updated : 2026-03-09 14:16


NVD link : CVE-2025-14558

Mitre link : CVE-2025-14558

CVE.ORG link : CVE-2025-14558


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation