Denial-of-Service Vulnerability in SoftEther VPN Developer Edition
CVE-2026-39312
7.5HIGH
What is CVE-2026-39312?
SoftEther VPN Developer Edition versions up to 5.2.5188 are susceptible to a denial-of-service vulnerability that enables unauthenticated attackers to crash the vpnserver process. This can be achieved by sending a single, malformed EAP-TLS packet over raw L2TP (UDP/1701), effectively terminating all active VPN sessions. The flaw presents significant risks for users relying on this VPN solution for secure communication.
Affected Version(s)
SoftEtherVPN <= 5.2.5188
