CVE-2025-45480
Received Received - Intake

Link Spoofing in Floodlight SDN Controller

Vulnerability report for CVE-2025-45480, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-13

Last updated on: 2026-09-13

Assigner: MITRE

Description

Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-13
Last Modified
2026-09-13
Generated
2026-09-14
AI Q&A
2026-09-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
floodlight floodlight From 71fe8a7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-669 The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a topology boundary identification flaw in the Floodlight SDN controller that disrupts host communication. It occurs when the controller processes high-layer protocol packets, causing it to misclassify ports as non-boundaries instead of topology boundaries. This prevents packet forwarding and flow rule deployment, breaking communication between hosts.

Detection Guidance

Detecting this vulnerability requires monitoring Floodlight controller logs for misclassified ports or unusual LLDP packet processing. Check for ports marked as non-boundaries despite connecting hosts. Use Floodlight's REST API to query topology data and verify boundary classifications. Monitor for dropped packets or failed flow rule installations between SDN and traditional switches.

Impact Analysis

An attacker can exploit this by spoofing links, sending crafted LLDP packets to manipulate the controller's topology perception. This leads to denial-of-service conditions where hosts connected to SDN switches cannot communicate with other network segments or malicious hosts.

Compliance Impact

This vulnerability disrupts host communication via link spoofing, which could lead to unauthorized network access or data interception. Such disruptions may violate data integrity and availability requirements in GDPR and HIPAA, potentially causing compliance breaches if sensitive data is exposed or inaccessible during an attack.

Mitigation Strategies

Update Floodlight to the latest patched version. Disable LLDP processing on untrusted ports or implement strict input validation for LLDP packets. Configure Floodlight to ignore spoofed LLDP packets by enabling topology verification features. Restrict access to the controller's management interface and monitor network traffic for anomalous LLDP floods.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-45480. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart