ma-personal.notion.site
https://ma-personal.notion.site/simpledns-vuln?source=copy_link CVE-2025-61430
MEDIUM
Record summary
CVE-2025-61430 has a selected CVSS score of 6.5 (medium).
Description
Improper handling of DNS over TCP in Simple DNS Plus v9 allows a remote attacker with querying access to the DNS server to cause the server to return request payloads from other clients. This happens when the TCP length prefix is malformed (len differs from actual packet len), and due to a concurrency/buffering issue, even when the lengths match. A length prefix that is smaller than the actual packet size increases information leakage. In summary, this vulnerability allows an attacker to see DNS queries of other clients.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 24, 2025 · Source: CVE List
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-61430 incognitotgt.me
https://www.incognitotgt.me/blog/simpledns-vuln