
apparently we’re now assigning CVEs with a 9.1 CVSS for RFC-compliant implementations of UPnP running on ISP-specific residential routers. this shit has lost all meaning. https://www.cve.org/CVERecord?id=CVE-2025-45422
Post summary
The post comments on CVE-2025-45422, noting a high CVSS score for UPnP on ISP routers, but offers no PoC, exploit, patch information, or evidence of active use—merely expressing frustration with the CVE process.

