CVE-2025-40943: exploitation status and patch state
CVE-2025-40943 · CVSS 9.6 CRITICAL · EPSS <1%
Affected devices do not properly sanitize contents of trace files. This could allow an attacker to inject code through social engineering a legitimate user to import a specially crafted trace file
Is CVE-2025-40943 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at <1%.
Public exploit code: none found in monitored sources.