Executive brief
Dual DHCP DNS Server is a combined networking service used to manage IP addresses and domain name lookups on local networks. A vulnerability in how it handles internet traffic allows remote attackers to trick the server into storing fake website records. This could lead to users being redirected to malicious websites, potentially resulting in data theft or malware infections.
Technical details
Dual DHCP DNS Server (v8.01 and earlier) contains a DNS cache poisoning vulnerability due to improper request/response correlation. The server's forwarder reuses the client's original 16-bit Transaction ID (TXID) for upstream queries instead of generating a random one, and it fails to validate that incoming UDP responses originate from the configured upstream DNS server's IP address. An unauthenticated remote attacker can exploit this by sending forged DNS responses that match a pending TXID, allowing them to inject malicious entries into the DNS cache. This can result in the redirection of network traffic to attacker-controlled destinations. As of the disclosure date, no patch is available.
Affected products
- DualServer Dual DHCP DNS Server up to and including 8.01
Timeline
- 2025-11-31: disclosed: Initial contact with vendor by researchers
- 2026-04-07: advisory: Public disclosure and CVE assignment