CVE-2025-68615: Net-SNMP SnmpTrapd Agent Message Stack-based Buffer Overflow Remote Code Execution Vulnerability
net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Net-SNMP. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SnmpTrapd service, which listens on UDP port 162 by default. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account.
— ZDI
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
net-snmp/snmptrapdto a version that resolves this vulnerability.Fixed in 5.9.5 - Upgrade
Upgrade
net-snmp/snmptrapdto a version that resolves this vulnerability.Fixed in 5.10.pre2
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68615?
CVE-2025-68615 has a critical severity level due to the potential for a buffer overflow that can crash the snmptrapd daemon.
How do I fix CVE-2025-68615?
You can fix CVE-2025-68615 by updating net-snmp to versions 5.9.5 or later, or 5.10.pre2 or later.
What products are affected by CVE-2025-68615?
CVE-2025-68615 affects net-snmp versions prior to 5.9.5 and 5.10.pre2.
What happens if I do not address CVE-2025-68615?
If not addressed, CVE-2025-68615 can lead to denial of service as the snmptrapd daemon may crash upon receiving specially crafted packets.
When was CVE-2025-68615 reported?
CVE-2025-68615 was reported before the patches were made available in versions 5.9.5 and 5.10.pre2.