The full story
CVE-2025-40910: Net:IP:LPM version 1.10 for Perl does not properly consider leading zero characters in IP CIDR address strings, which could allow attackers to bypas. No exploitation flag is present in the retained CyberDeltaForce data at this time; that status can change as vendor and threat-intelligence reporting develops. 10 for Perl does not properly consider leading zero characters in IP CIDR address strings, which could allow attackers to bypass access control that is based on IP addresses.
CVE-2025-40910 is a newly disclosed security weakness in Net:IP:LPM. CVE-2025-40910 currently carries a MEDIUM 6 5 severity signal in the retained vulnerability data. the development is primarily about a software weakness.
Risk depends on whether the affected product and versions are present, whether the vulnerable function is reachable, whether exploitation is public or active, and what privileges the affected process carries. A security weakness in Net:IP:LPM is being tracked as CVE-2025-40910. The issue currently carries a MEDIUM 6 5 severity signal in the CyberDeltaForce record.
The operational question is not simply the severity score, but whether the affected component is deployed, reachable, business-critical and protected by compensating controls. If you use the affected technology, first check whether the vulnerable component is actually present and reachable. The current severity assessment is MEDIUM 6 5.
Real risk depends on exposure, exploitability, compensating controls and the importance of the affected asset—not the CVSS number alone. CVE-2025-40910 affects Net:IP:LPM. The issue is tracked as CVE-2025-40910.
The current record lists the severity as MEDIUM 6.5. The current record does not mark the vulnerability as actively exploited. NIST NVD published the primary report used for this article on Sep 7, 2026.
Inventory affected products and versions. Validate external and internal reachability of the vulnerable function. Apply the vendor fix or mitigation and review telemetry for exploitation indicators when available.
The story is primarily about a software weakness.
What the reporting is based on
CVE-2025-40910: Net:IP:LPM version 1.10 for Perl does not properly consider leading zero characters in IP CIDR address strings, which could allow attackers to bypas
Net:IP:LPM version 1.10 for Perl does not properly consider leading zero characters in IP CIDR address strings, which could allow attackers to bypass access control that is based on IP addresses. Leading zeros are used to indicate octal numbers, which can confuse users who are intentionally using octal notation, as well as users who believe they are using decimal notation.
Open sourceReporting ends here. The sections below are CyberDeltaForce analysis and defender-focused interpretation.
What this means
The story is primarily about a software weakness. Risk depends on whether the affected product and versions are present, whether the vulnerable function is reachable, whether exploitation is public or active, and what privileges the affected process carries.
What security teams should check now
- Inventory affected products and versions.
- Validate external and internal reachability of the vulnerable function.
- Apply the vendor fix or mitigation and review telemetry for exploitation indicators when available.
What is not yet confirmed
- Available reporting does not currently indicate exploitation, but that can change as vendor, government or threat-intelligence reporting develops.