LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2025-69809

CVE-2025-69809 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: March 17, 2026

p2r3 Bareiron - Remote Code Execution

Published: March 16, 2026Updated: March 17, 2026Remote Exploitable

Overview

p2r3 Bareiron contains a write-what-where condition caused by improper memory write handling in commit 8e4d40, letting unauthenticated attackers execute arbitrary code via crafted packets.

Severity & Score

Severity: Critical
CVSS Score: 9.8
EPSS Score: 3.6%(Probability of exploitation in next 30 days)

Impact

Unauthenticated attackers can execute arbitrary code remotely, potentially taking full control of the system.

Mitigation

Update to the latest version including fixes after commit 8e4d40.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 16, 2026

šŸ”“ CVE-2025-69809 - Critical (9.8) A write-what-where condition in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to write arbitrary values to memory, enabling arbitrary code execution via a crafted packet. šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2025-69809/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 16, 2026

šŸ”“ CVE-2025-69809 - Critical (9.8) A write-what-where condition in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to write arbitrary values to memory, enabling arbitrary code execution via a crafted packet. šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2025-69809/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2025-69809
Severity
Critical
CVSS Score
9.8
Type
undefined
Status
unconfirmed
EPSS
3.6%
Social Posts
2

CWE

  • CWE-123

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

3.6%Probability of exploitation in the next 30 days