Out-of-bounds read in OpenWrt - CVE-2025-62525
Published: April 24, 2026
OpenWrt
Detailed vulnerability description
The vulnerability allows a local user to read and write arbitrary kernel memory.
The vulnerability exists due to improper input validation in the ltq-ptm driver ioctls when processing ioctl requests. A local user can send crafted ioctl requests to read and write arbitrary kernel memory.
The issue affects systems using the ltq-ptm driver for DSL datapath operation in PTM mode on supported lantiq targets.