OPNsense Forum

English Forums => 25.1, 25.4 Series => Topic started by: Ametite on May 29, 2025, 09:34:17 AM

Title: CVE-2025-32801 - Kea DHCP 2.6.x (x< 3)
Post by: Ametite on May 29, 2025, 09:34:17 AM
Good morning, everyone. I apologize if this is not the correct section; I'm relatively new here.
This morning, I received a CVE report from our cybersecurity agency regarding CVE on Kea DHCP. I checked the packet version in OPNsense, and it appears to be affected in the latest available version of OPNsense.

https://www.acn.gov.it/portale/en/w/aggiornamenti-di-sicurezza-per-prodotti-isc

https://www.cve.org/CVERecord?id=CVE-2025-32801

This is just as report :)
Title: Re: CVE-2025-32801 - Kea DHCP 2.6.x (x< 3)
Post by: elenagilbert on September 24, 2025, 05:58:52 PM
Quote from: Ametite on May 29, 2025, 09:34:17 AMGood morning, everyone. I apologize if this is not the correct section; I'm relatively new here.
This morning, I received a CVE report from our cybersecurity agency regarding CVE on Kea DHCP. I checked the packet version in OPNsense, and it appears to be affected in the latest available version of OPNsense.

https://www.acn.gov.it/portale/en/w/aggiornamenti-di-sicurezza-per-prodotti-isc

https://www.cve.org/CVERecord?id=CVE-2025-32801

This is just as report :)
Geometry Dash (https://geometrydashwave.io/)
Thanks for sharing! I have reviewed this CVE and found that the current Kea DHCP version on OPNsense is affected. Luckily, this is just a report, so we can still plan to patch soon. Has anyone tried to update or have a workaround?
Title: Re: CVE-2025-32801 - Kea DHCP 2.6.x (x< 3)
Post by: Patrick M. Hausen on September 24, 2025, 06:02:36 PM
It's a firewall appliance. Nobody who is not alread a firewall administrator has access to Kea configuration or API. This CVE is irrelevant in our context.