ZeroHour

CVE-2014-3931

KEVniche

Remote Buffer Overflow in Multi-Router Looking Glass (MRLG)

CISA: Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability

CVSS
EPSS
29%p98
Published
KEV added
AI analysis

Multi-Router Looking Glass (MRLG), a web-based tool used by network operators to run public router/BGP looking-glass services, contains a buffer overflow flaw (CWE-119) that can be triggered by remote attackers via crafted input to the network-facing service. The flaw allows arbitrary memory writes and memory corruption, potentially leading to code execution or denial of service under the privileges of the MRLG service. Organizations running reachable MRLG instances — typically ISPs, exchange points, and enterprise network teams exposing looking-glass pages — are affected. CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2025-07-07, indicating confirmed in-the-wild exploitation, though no public proof-of-concept is known. EPSS currently estimates a 29% probability of exploitation within 30 days, placing it in the 98th percentile.

What to do: Per the CISA KEV required action, apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable, and follow BOD 22-01 guidance for cloud services; no fixed version is specified in the available data, so check with the maintainer for the latest release. Inventory internet-facing looking-glass pages for MRLG and, where patching is not possible, restrict public access to the service or remove it from exposure.

Affected
Looking Glass Multi-Router Looking Glass (MRLG)
Estimated exposure
nichelikely hundreds to a few thousand internet-facing MRLG instances — No vendor or registry install counts exist for this product; MRLG is a niche BGP looking-glass tool deployed mainly by ISPs, exchange points, and research networks, and public looking-glass directories and internet scans suggest only a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Multi-Router Looking Glass (MRLG) contains a buffer overflow vulnerability that could allow remote attackers to cause an arbitrary memory write and memory corruption.

CISA Known Exploited Vulnerability
Affected
Looking Glass Multi-Router Looking Glass (MRLG)
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
Looking Glass
Products
Multi-Router Looking Glass (MRLG)
Weakness
CWE-119

In the news