Executive brief
Multi-Router Looking Glass (MRLG), a tool used by network administrators to view routing information from various network devices, contains a critical security flaw. An attacker can exploit this vulnerability remotely to corrupt the system's memory, potentially leading to a complete takeover of the server. This could allow unauthorized access to sensitive network topology data or disrupt network monitoring operations.
Technical details
A buffer overflow vulnerability exists in the fastping.c component of Multi-Router Looking Glass (MRLG) prior to version 5.5.0. The flaw is classified as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer). A remote, unauthenticated attacker can exploit this by sending specially crafted requests to the application, leading to arbitrary memory writes and memory corruption. This can result in remote code execution (RCE) with the privileges of the MRLG process. The vulnerability has been observed being exploited in the wild and is included in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Affected products
- Multi-Router Looking Glass Project Multi-Router Looking Glass (MRLG) before 5.5.0
Timeline
- 2017-03-31: advisory: NVD Published Date
- 2025-07-07: kev added: Added to CISA KEV catalog
- 2025-07-07: exploited: Confirmed active exploitation by CISA