CVE-2025-40766
MEDIUMSINEC Traffic Analyzer < 3.0 - Denial of Service via Uncontrolled Docker Resource Consumption
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-40766. PoCs published by FurkanKAYAPINAR.
AI-analyzed exploit summary This tool checks if a remote DNS resolver supports EDNS Client Subnet (ECS), which may expose systems to cache poisoning or information leakage vulnerabilities. It sends a DNS query with an ECS option and detects whether ECS is enabled on the target DNS resolver.
Description
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application runs docker containers without adequate resource and security limitations. This could allow an attacker to perform a denial-of-service (DoS) attack.
Exploits (1)
This tool checks if a remote DNS resolver supports EDNS Client Subnet (ECS), which may expose systems to cache poisoning or information leakage vulnerabilities. It sends a DNS query with an ECS option and detects whether ECS is enabled on the target DNS resolver.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H