Back to overview

CVE-2025-54426

CRITICAL
9.9
CVSS 4.0
Description
Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. In versions prior to commit 36f70d1, the Curve25519Add and Curve25519ScalarMul precompiles incorrectly handle invalid Ristretto point representations. Instead of returning an error, they silently treat invalid input bytes as the Ristretto identity element, leading to potentially incorrect cryptographic results. This is fixed in commit 36f70d1.

Metadata

CVE ID
CVE-2025-54426
State
PUBLISHED
Assigner
GitHub_M
Reserved
2025-07-21 23:18 UTC
Published
2025-07-28 20:08 UTC
Last updated
2025-07-28 20:26 UTC
Primary CWE
CWE-327
CWE-327: Use of a Broken or Risky Cryptographic Algorithm
Vendor / Product
polkadot-evm / frontier
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:H/SA:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
polkadot-evm frontier < 36f70d1
Weakness (CWE)
CWESourceDescription
CWE-327 cna CWE-327: Use of a Broken or Risky Cryptographic Algorithm
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:H/SA:N
References (4)
Back to overview