Integer Underflow Vulnerability in strongSwan's EAP-MSCHAPv2 Plugin
CVE-2025-62291

8.1HIGH

Key Information:

Vendor

Strongswan

Vendor
CVE Published:
16 January 2026

What is CVE-2025-62291?

The eap-mschapv2 plugin in strongSwan prior to version 6.0.3 is susceptible to an integer underflow vulnerability. This occurs when a malicious EAP-MSCHAPv2 server sends a specifically crafted message of size between 6 and 8 bytes. The flaw may result in a heap-based buffer overflow, potentially allowing unauthorized access or manipulation of sensitive data. It is crucial for users and administrators of strongSwan to upgrade to the latest version to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

strongSwan 4.2.12 < 6.0.3

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.