CVE-2025-65882: Openmptcprouter

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade-helper/src/tools/sysupgrade.c in function create_xor_ipad_opad allowing attackers to potentially write arbitrary files or execute arbitrary commands.

Affected products

Published 2025-12-09. Last modified 2026-07-05.