Impact
AdGuard Home forwards DoQ queries to UDP DNS upstreams; before version 0.107.75 this forwarding strips backend state by sending queries with dns_id or txid set to zero and exposes an ICMP source‑port oracle. The weakened DNS response matching allows attackers to forge or spoof responses and to cause denial‑of‑service through failed validation checks, mapping to CWE‑330 and CWE‑346 weaknesses.
Affected Systems
The flaw affects AdguardTeam’s AdGuard Home product, specifically versions prior to 0.107.75. Upgrading to 0.107.75 or later removes the vulnerability.
Risk and Exploitability
With a CVSS score of 6.3 the risk is moderate, and the EPSS score of less than 1 % indicates a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, suggesting no documented active exploitation yet. The attack likely occurs from a network‑level attacker who can send DoQ queries to the affected AdGuard Home instance; however, this is inferred from the description that the issue resides in the DoQ‑to‑UDP forwarding path.
OpenCVE Enrichment
Github GHSA