CVE-2025-14558

CVE-2025-14558: Remote code execution via ND6 Router Advertisements

Vendor Freebsd
Product FreeBSD
Weakness CWE-20 · Input validation
Published March 9, 2026
Last update March 10, 2026

CVSS base score

What the vulnerability does

01Description

The rtsol(8) and rtsold(8) programs do not validate the domain search list options provided in router advertisement messages; the option body is passed to resolvconf(8) unmodified. resolvconf(8) is a shell script which does not validate its input. A lack of quoting meant that shell commands pass as input to resolvconf(8) may be executed.

Key dates

02Disclosure timeline

March 9, 2026 CVE published
March 10, 2026 Record updated