Vulnerability Description
Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending sequences being neutralized, which allows additional directives to be introduced into that file. The configuration interface accepts changes without authenticating or verifying the origin of the requester. The injected configuration persists on disk across restarts of the client and the operating system, and the VPN connection continues to function normally, so there is no behavioral change visible to the user.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-24
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-02
- https://www.ixon.cloud/Advisories/ADV-2026-08-05.pdf
FAQ
What is CVE-2026-75925?
CVE-2026-75925 is a vulnerability with a CVSS score of 9.6 (CRITICAL). Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are writt...
How severe is CVE-2026-75925?
CVE-2026-75925 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-75925?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.