Input validation error in PPP - #VU151455

 

Input validation error in PPP - #VU151455

Published: September 19, 2026


Vulnerability identifier: #VU151455
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject routes into the pppd host.

The vulnerability exists due to improper input validation in the dhcpv6relay plugin when processing DHCPv6 frames received from a DHCPv6 client. A remote attacker can send crafted DHCPv6 frames to inject routes into the pppd host.

Only deployments where the local pppd provides IPv6 connectivity to the peer are affected.


Affected software

PPP

Remediation

Install security update from vendor's website.

PPP - update to 2.5.4

External References

Related Security Bulletins