CVE-2025-40910
Net::IP::LPM version 1.10 for Perl does not properly consider leading zero characters in IP CIDR address strings, which could allow attackers to bypass access control that is based on IP addresses. Leading zeros are used to indicate octal numbers, which can confuse users who are intentionally using octal notation, as well as users who believe they are using decimal notation.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS probability
- 0.29%
- CWE
- CWE-1287
- Published
- 2025-06-27
- Last modified
- 2026-09-07
Affected products
- TPODER Net::IP::LPM
Weakness type
Related vulnerabilities
- CVE-2024-4879 — Jelly Template Injection Vulnerability in ServiceNow UI Macros
- CVE-2024-6298 — remote code execution
- CVE-2024-51551 — Default Credentials
- CVE-2024-51550 — Data Validation / Sanitization
- CVE-2021-32024 — A remote code execution vulnerability in the BMP image codec of BlackBerry QNX SDP version(s) 6.4 to 7.1 could allow an
- CVE-2021-43802 — Admin privilege escalation and arbitrary code execution via malicious *.etherpad imports
- CVE-2024-35213 — Vulnerability in SGI Image Codec Impacts BlackBerry QNX Software Development Platform (SDP)
- CVE-2024-30395 — Junos OS and Junos OS Evolved: A malformed BGP tunnel encapsulation attribute will lead to an rpd crash