# CVE-2025-32743

## Summary

- **CVE ID:** CVE-2025-32743
- **Severity:** CRITICAL
- **CVSS Score:** 9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-392
- **Published:** Apr 10, 2025
- **Last Modified:** Mar 13, 2026

## Description

In ConnMan through 1.44, the lookup string in ns_resolv in dnsproxy.c can be NULL or an empty string when the TC (Truncated) bit is set in a DNS response. This allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code, because those lookup values lead to incorrect length calculations and incorrect memcpy operations.

## Affected Products

- ConnMan — ConnMan (0)

## References

- [CNA](https://web.git.kernel.org/pub/scm/network/connman/connman.git/tree/src/dnsproxy.c?h=1.44#n1688)
- [CNA](https://lapis-sawfish-be3.notion.site/0-click-Vulnerability-in-Comman-1-43_v3-1cadc00d01d080b0b3b9c46a6da584cc)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.52%
- **EPSS Percentile:** 42.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._