Impact
Unbound versions 1.7.0 through 1.25.1 allow a resolver to treat a configured primary hostname for zone transfer as a valid endpoint even when that hostname resolves to a BOGUS A or AAAA record. Because the resolver does not require a valid signature for the primary hostname, an attacker that can spoof the DNS records for that hostname becomes the zone transfer primary. Presented with the attacker‑controlled zone data, the resolver accepts it and replaces its entire response policy zone, effectively allowing a successful zone takeover and policy manipulation.
Affected Systems
NLnet Labs Unbound 1.7.0 and all subsequent releases up to and including 1.25.1 are affected when an authenticated RPZ zone exercises a primary hostname that resolves to a non‑existent address record. Versions 1.25.2 and newer contain the fix and are not vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of <1% suggests a very low likelihood of exploitation in the wild, yet the vulnerability is publicly documented and could be used if an attacker can influence the DNS for the hostname. Based on the description, it is inferred that controlling or spoofing the primary hostname’s A/AAAA record requires the attacker to have influence over external DNS for that hostname, which may be relatively straightforward in some environments. The vulnerability is not listed in the CISA KEV catalog, and the attack requires no valid RRSIG; thus the exploitation path is primarily via hostname spoofing and unsolicited zone transfer acceptance.
OpenCVE Enrichment