CVE-2018-18408: Broadcom Tcpreplay

Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.

A use-after-free was discovered in the tcpbridge binary of Tcpreplay 4.3.0 beta1. The issue gets triggered in the function post_args() at tcpbridge.c, causing a denial of service or possibly unspecified other impact.

Affected products

Published 2018-10-17. Last modified 2026-06-17.