IXON VPN Client

Summary

A critical vulnerability (CVE-2026-75925) has been identified in IXON VPN Client versions prior to 1.4.7. Successful exploitation allows attackers to achieve remote code execution with elevated privileges on affected systems. The vulnerability stems from improper neutralization of CRLF sequences, enabling injection of malicious directives into configuration files.

IFF Assessment

FOE

This vulnerability allows for remote code execution with elevated privileges, posing a significant risk to defenders by enabling attackers to compromise systems.

Severity

9.6 Critical

The CVSS score of 9.6 indicates a critical severity, reflecting the potential for remote code execution with elevated privileges (SYSTEM or root) and the presence of an unauthenticated attack vector.

Defender Context

This vulnerability in the IXON VPN Client allows for critical remote code execution, impacting sectors like energy and IT. Defenders should prioritize updating the IXON VPN Client to version 1.4.7 or later to mitigate this risk. The continued functionality of the VPN despite the vulnerability means it could be exploited without immediate user detection.

Read Full Story →