A critical vulnerability (CVE-2025-68615) has been identified in the Net-SNMP snmptrapd daemon, which can be exploited by sending a specially crafted packet to cause a buffer overflow and crash the service. The flaw affects versions prior to 5.9.5 and 5.10.pre2, and has been addressed in these patched releases. The vulnerability is remotely exploitable and does not require authentication, making it a significant risk for organizations running affected versions of Net-SNMP.
Technical analysis reveals that the vulnerability stems from improper validation of user-supplied data length before copying it to a fixed-length stack-based buffer within the snmptrapd service, which listens on UDP port 162 by default. Successful exploitation allows remote attackers to execute arbitrary code in the context of the service account. Net-SNMP has released security updates to mitigate this issue, and users are strongly advised to upgrade to the latest versions to protect their systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2025-68615 was publicly disclosed as a critical vulnerability in Net-SNMP's snmptrapd daemon with a CVSS 3.1 score of 9.8. Advisories described it as a stack-based/buffer overflow remotely exploitable without authentication or user interaction.
Net-SNMP released updates addressing CVE-2025-68615 in versions 5.9.5 and 5.10.pre2. The flaw affects earlier versions of snmptrapd and can lead to denial of service or possible remote code execution via crafted packets sent to UDP port 162.
The Net-SNMP snmptrapd buffer overflow vulnerability later assigned CVE-2025-68615 was reported on July 25, 2025. The issue was credited to buddurid and involved improper length validation that could enable remote, unauthenticated exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
thecyberexpress.com
Open sourcecybersecuritynews.com
Open sourcecvefeed.io
Open sourcezerodayinitiative.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.