CVE-2025-25565
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2025-25565 is a newly disclosed vulnerability affecting SoftEther VPN 5.02.5187. This issue involves a buffer overflow flaw in the Command.c file, specifically in the PtMakeCert and PtMakeCert2048 functions. maliciously crafted input can cause the buffer to overflow, potentially leading to arbitrary code execution, and subsequent compromise of the affected system. It is recommended that users upgrade to the latest version of SoftEther VPN to mitigate this risk. Additionally, network segmentation and firewall rules can help limit the impact of potential exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- SoftEther VPN
Affected Vendors
- SoftEther Corporation