IXON VPN Client
Summary
A critical vulnerability (CVE-2026-75925) has been identified in IXON VPN Client versions prior to 1.4.7. Successful exploitation allows attackers to achieve remote code execution with elevated privileges on affected systems. The vulnerability stems from improper neutralization of CRLF sequences, enabling injection of malicious directives into configuration files.
IFF Assessment
This vulnerability allows for remote code execution with elevated privileges, posing a significant risk to defenders by enabling attackers to compromise systems.
Severity
The CVSS score of 9.6 indicates a critical severity, reflecting the potential for remote code execution with elevated privileges (SYSTEM or root) and the presence of an unauthenticated attack vector.
Defender Context
This vulnerability in the IXON VPN Client allows for critical remote code execution, impacting sectors like energy and IT. Defenders should prioritize updating the IXON VPN Client to version 1.4.7 or later to mitigate this risk. The continued functionality of the VPN despite the vulnerability means it could be exploited without immediate user detection.