Host Header Injection Vulnerability in Hotspot Shield VPN Client
CVE-2025-40710
What is CVE-2025-40710?
A Host Header Injection vulnerability exists in the Hotspot Shield VPN Client that allows an attacker to manipulate host headers when routing traffic through the VPN. This can lead to unintended HTTP request redirections and may expose users to risks, including the possibility of sending data to malicious servers. The vulnerability is rooted in the interpretation of host headers by the VPN client rather than any inherent flaw in the applications being accessed. As a result, attackers could exploit this issue to redirect user traffic to untrusted environments, potentially facilitating further attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Hotspot Shield VPN client 12.9.2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
