Traffic Control Vulnerability in Sliver Command Control Framework by BishopFox
CVE-2025-27093
What is CVE-2025-27093?
The Sliver command and control framework, developed by BishopFox, has a traffic control vulnerability in its Wireguard netstack. In versions 1.5.43 and earlier, as well as in the development version 1.6.0-dev, there is an absence of traffic restrictions between Wireguard clients. This lack of traffic control can potentially lead to unauthorized communication between clients, which may result in leaked or compromised keypairs being exploited. Furthermore, it allows for port forwardings to be accessible by other implants, enhancing the risk for operators and increasing the attack surface.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
sliver <= 1.5.43
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved