CVE Tools

CVE-2025-11411

Possible domain hijacking via promiscuous records in the authority section

Published: Oct 22, 2025Updated: Dec 5, 2025 Sources: CVE List NVD BDUCWE-349

Description

NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive DNS replies in the authority section can be used to trick resolvers to update their delegation information for the zone. Usually these RRSets are used to update the resolver's knowledge of the zone's name servers. A malicious actor can exploit the possible poisonous effect by injecting NS RRSets (and possibly their respective address records) in a reply. This could be done for example by trying to spoof a packet or fragmentation attacks. Unbound would then proceed to update the NS RRSet data it already has since the new data has enough trust for it, i.e., in-zone data for the delegation point. Unbound 1.24.1 includes a fix that scrubs unsolicited NS RRSets (and their respective address records) from replies mitigating the possible poison effect. Unbound 1.24.2 includes an additional fix that scrubs unsolicited NS RRSets (and their respective address records) from YXDOMAIN and non-referral nodata replies, further mitigating the possible poison effect.

CVSS Vector Breakdown

AV:AAC:LC:NI:HA:N
Exploitability
AV:AAccess Vector
Adjacent Network
AC:LAccess Complexity
Low
Impact
C:NConfidentiality
None
I:HIntegrity
H
A:NAvailability
None

Weaknesses

Affected Products

nlnet labsoss-projectNetworking Infrastructureaka unbound, routinator, bcder
ао «сбертех»commercialRUOperating Systemsaka ao sbertech, сбертех
and 1 more affected products View all →

Exploitability

Official Patch Available

References

and 10 more references View all →

Timeline

Published
Oct 22, 2025
Last Updated
Dec 5, 2025

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2025-11411 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows