PatchSiren cyber security CVE debrief
CVE-2025-45480 projectfloodlight CVE debrief
A vulnerability in Floodlight 71fe8a7 allows for the disruption of host communication via link spoofing due to a port misclassification as a non-boundary port. This issue can impact network reliability and security, particularly in environments where Floodlight is used for network management. Network administrators and security teams should assess their exposure and verify their inventory to understand the potential impact on their systems. The vulnerability highlights the importance of accurate port classification and the need for vigilant network monitoring.
- Vendor
- projectfloodlight
- Product
- Floodlight
- CVSS
- LOW 3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-13
- Original CVE updated
- 2026-09-22
- Advisory published
- 2026-09-13
- Advisory updated
- 2026-09-22
Who should care
Network administrators and security teams responsible for Floodlight deployments should assess their exposure and verify their inventory. This vulnerability can impact network reliability and security, making it essential for these teams to understand the potential risks and take appropriate measures to mitigate them. Additionally, operators of Floodlight-managed networks and platforms should review their current and
Why it matters
CVE-2025-45480 is a vulnerability in Floodlight 71fe8a7 that allows for link spoofing, potentially disrupting host communication. Network administrators and security teams should assess exposure, verify inventory, and monitor for suspicious activity.
- Network communication disruption
- Potential for unauthorized access
- Need for verification of Floodlight configurations
Technical summary
Floodlight 71fe8a7 is vulnerable to link spoofing attacks due to incorrect port classification. This vulnerability allows attackers to disrupt host communication, potentially leading to network instability. The issue arises from a misclassification of a port as a non-boundary port, which can be exploited to spoof links and disrupt network operations. Understanding the technical details of this vulnerability is crucial for developing effective mitigations and ensuring the security of Floodlight deployments.
Defensive priority
Network administrators and security teams should assess exposure and verify inventory, particularly for Floodlight deployments.
Recommended defensive actions
- Verify Floodlight inventory and configurations
- Assess network exposure and boundary port settings
- Monitor for suspicious network activity
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. Further verification is required to determine affected versions and remediation.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-45480 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-45480
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-45480 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-45480
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/floodlight/floodlight/issues/873
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.