Command Execution Vulnerability in IXON VPN Client by IXON
CVE-2026-75925

9.4CRITICAL

Key Information:

Vendor

Ixon

Vendor
CVE Published:
4 September 2026

What is CVE-2026-75925?

The IXON VPN Client, prior to version 1.4.7, exhibits a vulnerability where improper handling of carriage return and line feed (CRLF) sequences allows attackers to execute arbitrary commands with elevated privileges. This occurs because configuration values provided to the local service are stored in a file that a privileged subprocess later reads. Without proper neutralization, malicious directives can be introduced into this file. Notably, there are no authentication checks on the configuration interface, enabling unauthorized changes. Additionally, any injected configurations can persist across client and system restarts, maintaining VPN functionality without visible indicators of compromise.

Affected Version(s)

IXON VPN Client 0 < 1.4.7

IXON VPN Client 1.4.7

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Luuk van Rheden of IXON discovered this vulnerability.
Stan van Duijnhoven of IXON reported this vulnerability to CISA.
.