CVE-2025-25565

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 12, 2025
Updated: Apr 2, 2025
CWE ID 120

Summary

CVE-2025-25565 is a newly disclosed vulnerability affecting SoftEther VPN 5.02.5187. This issue involves a buffer overflow flaw in the Command.c file, specifically in the PtMakeCert and PtMakeCert2048 functions. maliciously crafted input can cause the buffer to overflow, potentially leading to arbitrary code execution, and subsequent compromise of the affected system. It is recommended that users upgrade to the latest version of SoftEther VPN to mitigate this risk. Additionally, network segmentation and firewall rules can help limit the impact of potential exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • SoftEther VPN

Affected Vendors

  • SoftEther Corporation