CVE-2025-9649: appneta tcpreplay send_packets.c calc_sleep_time divide by zero
A security vulnerability has been detected in appneta tcpreplay 4.5.1. Impacted is the function calcsleeptime of the file sendpackets.c. Such manipulation leads to divide by zero. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 4.5.3-beta3 is recommended to address this issue. It is advisable to upgrade the affected component. The vendor confirms in a GitHub issue reply: "Was able to reproduce in 6fcbf03 but NOT 4.5.3-beta3."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9649?
CVE-2025-9649 has a high severity due to the potential for local exploitation leading to a divide by zero error.
How do I fix CVE-2025-9649?
To fix CVE-2025-9649, upgrade AppNeta tcpreplay to version 4.5.2 or later, which addresses the vulnerability.
What systems are affected by CVE-2025-9649?
CVE-2025-9649 affects AppNeta tcpreplay version 4.5.1.
What type of vulnerability is CVE-2025-9649?
CVE-2025-9649 is a divide by zero vulnerability resulting from a flaw in the calc_sleep_time function.
Is CVE-2025-9649 publicly disclosed?
Yes, CVE-2025-9649 has been publicly disclosed and is known to be exploitable.