SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-75925

CRITICAL · CVSS 9.6 EPSS 0.67% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The IXON VPN Client prior to version 1.4.7 is vulnerable due to improper handling of CRLF sequences, allowing attackers to inject malicious commands that execute with root or SYSTEM privileges. This vulnerability can lead to persistent unauthorized access, as the injected configurations remain on disk and are not visible to users. Organizations using this VPN client should prioritize remediation to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75925
Severity
CRITICAL
CVSS
9.6
EPSS
0.67%

Original NVD Description

Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending sequences being neutralized, which allows additional directives to be introduced into that file. The configuration interface accepts changes without authenticating or verifying the origin of the requester. The injected configuration persists on disk across restarts of the client and the operating system, and the VPN connection continues to function normally, so there is no behavioral change visible to the user.