Input validation error in PPP - #VU151455
Published: September 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject routes into the pppd host.
The vulnerability exists due to improper input validation in the dhcpv6relay plugin when processing DHCPv6 frames received from a DHCPv6 client. A remote attacker can send crafted DHCPv6 frames to inject routes into the pppd host.
Only deployments where the local pppd provides IPv6 connectivity to the peer are affected.