CVE-2025-65882

An issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade-helper/src/tools/sysupgrade.c in function create_xor_ipad_opad allowing attackers to potentially write arbitrary files or execute arbitrary commands.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openmptcprouter:openmptcprouter:*:*:*:*:*:*:*:*

History

02 Jan 2026, 21:30

Type Values Removed Values Added
First Time Openmptcprouter
Openmptcprouter openmptcprouter
References () http://openmptcprouter.com - () http://openmptcprouter.com - Product
References () https://gist.github.com/AradCohen/939ee50d60c4d2bd555a364615a5ab9c - () https://gist.github.com/AradCohen/939ee50d60c4d2bd555a364615a5ab9c - Exploit, Third Party Advisory
References () https://github.com/Ysurac/openmptcprouter/commit/09393d1c41a227bea7d5b85c0a06221b1302b25f - () https://github.com/Ysurac/openmptcprouter/commit/09393d1c41a227bea7d5b85c0a06221b1302b25f - Patch
CPE cpe:2.3:a:openmptcprouter:openmptcprouter:*:*:*:*:*:*:*:*

11 Dec 2025, 20:16

Type Values Removed Values Added
CWE CWE-78
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

09 Dec 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-09 19:15

Updated : 2026-01-02 21:30


NVD link : CVE-2025-65882

Mitre link : CVE-2025-65882

CVE.ORG link : CVE-2025-65882


JSON object : View

Products Affected

openmptcprouter

  • openmptcprouter
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')