Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-70957

EPSS 0.06% · P17
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-70957

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A Denial of Service (DoS) vulnerability was discovered in the TON Lite Server before v2024.09. The vulnerability arises from the handling of external arguments passed to locally executed "get methods." An attacker can inject a constructed Continuation object (an internal TVM type) that is normally restricted within the VM. When the TVM executes this malicious continuation, it consumes excessive CPU resources while accruing disproportionately low virtual gas costs. This "free" computation allows an attacker to monopolize the Lite Server's processing power, significantly reducing its throughput and causing a denial of service for legitimate users acting through the gateway.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
TON 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
TON是TON开源的一个区块链软件。 TON v2024.09之前版本存在安全漏洞,该漏洞源于处理外部参数不当,可能导致攻击者通过特制Continuation对象造成拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2025-70957

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-70957

登录查看更多情报信息。

Same Patch Batch · n/a · 2026-02-13 · 15 CVEs total

CVE-2025-70121free5GC 安全漏洞
CVE-2025-70956TON 安全漏洞
CVE-2025-70093opensourcepos 安全漏洞
CVE-2025-70091opensourcepos 安全漏洞
CVE-2025-70094opensourcepos 安全漏洞
CVE-2025-70123free5GC 安全漏洞
CVE-2025-70866Lavalite CMS 安全漏洞
CVE-2025-70122free5GC 安全漏洞
CVE-2025-70955TON 安全漏洞
CVE-2025-70954TON 安全漏洞
CVE-2025-70095opensourcepos 安全漏洞
CVE-2025-66676IOBit Unlocker 安全漏洞
CVE-2025-69633PrestaShop 安全漏洞
CVE-2025-69770MojoPortal CMS 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2025-70957

No comments yet


Leave a comment