CVE-2025-9386: appneta tcpreplay tcprewrite get.c get_l2len_protocol use after free
A vulnerability has been found in appneta tcpreplay up to 4.5.1. The impacted element is the function getl2lenprotocol of the file get.c of the component tcprewrite. Such manipulation leads to use after free. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. Upgrading to version 4.5.2-beta3 is sufficient to resolve this issue. You should upgrade the affected component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9386?
CVE-2025-9386 has a high severity due to its potential to lead to a local use-after-free vulnerability.
How do I fix CVE-2025-9386?
To fix CVE-2025-9386, upgrade AppNeta TCPreplay to version 4.5.2 or later.
Who is affected by CVE-2025-9386?
CVE-2025-9386 affects users of AppNeta TCPreplay versions up to and including 4.5.1.
What components are involved in CVE-2025-9386?
CVE-2025-9386 involves the get_l2len_protocol function within the tcprewrite component of AppNeta TCPreplay.
Is CVE-2025-9386 exploitative remotely?
No, CVE-2025-9386 requires the attack to be executed locally.