CVE-2025-10680

Published Oct 24, 2025

Last updated 5 months ago

CVSS high 8.8
Tunneling protocol

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-10680 affects OpenVPN versions 2.7_alpha1 through 2.7_beta1 on POSIX-based platforms. It involves a vulnerability where a remote, authenticated server can inject shell commands via DNS variables when the `--dns-updown` script option is used. Specifically, a malicious OpenVPN server could exploit this by injecting scripts. On Linux and similar systems, the DNS options are written to a temporary file that is then sourced by a script running as root, allowing for potential script injection attacks. The vulnerability has been addressed with proper input sanitization in later versions of OpenVPN.

Description
OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell commands via DNS variables when --dns-updown is in use
Source
security@openvpn.net
NVD status
Deferred

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

security@openvpn.net
CWE-78

Social media

Hype score
Not currently trending
  1. ⚠️ OpenVPN RCE Vulnerability CVE-2025-10680: High-severity flaw enabling authenticated VPN servers to execute OS commands on clients. Scope: OpenVPN Client (Linux, macOS) Requirement: --dns-updown enabled

    @cyberthreatzip

    10 Nov 2025

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. How was your weekend? Mine ended with a deep dive into the OpenSSH CVE-2025-10680 vulnerability which was not exactly relaxing, but definitely interesting🧐 [1/5]

    @LucianNitescu

    2 Nov 2025

    99 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. OpenVPN 2.7系プレリリースに高リスク脆弱性(CVE-2025-10680-悪意あるDNS設定でクライアント側スクリプト実行の恐れ https://t.co/VfX3KG8nkW #セキュリティ対策Lab #セキュリティ #Security

    @securityLab_jp

    31 Oct 2025

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨🚨CVE-2025-10680 (CVSS 8.8): Script-injection RCE in OpenVPN Client Malicious DNS servers can exploit unsanitized --dns and --dhcp-option parameters to inject commands executed on the client. Search by vul.cve Filter👉vul.cve="CVE-2025-10680" ZoomEye Dork👉app="OpenVPN

    @zoomeye_team

    29 Oct 2025

    1197 Impressions

    6 Retweets

    28 Likes

    7 Bookmarks

    0 Replies

    0 Quotes

  5. ⚠️⚠️ CVE-2025-10680: High 8.8/10 Script-injection RCE in OpenVPN client (affects 2.7_alpha1 → 2.7_beta1) — malicious VPN servers can push crafted --dns / --dhcp-option to the --dns-updown hook and inject commands on Unix clients (Linux/macOS) 🎯3.3m+ Results are fou

    @fofabot

    29 Oct 2025

    1622 Impressions

    10 Retweets

    28 Likes

    6 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨Alert🚨 CVE-2025-10680 : High-Severity OpenVPN Flaw Allows Script Injection on Linux/macOS via Malicious DNS Server 📊3.6M+ Services are found on the https://t.co/ysWb28BTvF yearly. 🔗Hunter Link:https://t.co/bjfitNwuTc 👇Query HUNTER : https://t.co/q9rtuGfZuz="OpenVP

    @HunterMapping

    29 Oct 2025

    5405 Impressions

    16 Retweets

    53 Likes

    25 Bookmarks

    1 Reply

    1 Quote

  7. 🚨 CVE-2025-10680: OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell commands via DNS variables when --dns-updown is in use CVSS: 8.8 Published: 2025-10-24 Advisory: https://t.co/hoEpxKMext

    @DarkWebInformer

    29 Oct 2025

    4262 Impressions

    4 Retweets

    20 Likes

    3 Bookmarks

    1 Reply

    0 Quotes

  8. OpenVPN Flaw CVE-2025-10680 Puts Linux/macOS Users at Risk via DNS - Update Now! Read the full report on - https://t.co/AABA41zOqX https://t.co/EKKofC32N1

    @cyberbivash

    28 Oct 2025

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. NVD - CVE-2025-10680 https://t.co/vTfEM8NUmr OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell commands via DNS variables when --dns-updown is in use

    @pHo9UBenaA

    28 Oct 2025

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. OpenVPN 2.7系(2.7_alpha1〜2.7_beta1)に、サーバーからクライアントへのDNS構成情報を通じて任意コマンドが実行される脆弱性(CVE-2025-10680)が確認されました。 https://t.co/gTgRHw5WBy

    @t_nihonmatsu

    28 Oct 2025

    426 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  11. OpenVPNの開発版に深刻な脆弱性(CVE-2025-10680、CVSS 8.8)が発見された。2.7_alpha1〜2.7_beta1が影響を受け、悪意あるVPNサーバに接続するとスクリプトインジェクションを介してクライアント側で任意コード実行が可

    @yousukezan

    28 Oct 2025

    1411 Impressions

    2 Retweets

    10 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  12. OpenVPN(クライアント)に深刻な脆弱性。CVE-2025-10680はCVSSスコア8.8で、悪意あるVPNサーバに接続することによりスクリプトインジェクションからの遠隔コード実行が成立。提示される--dnsと--dhcp-option引数の無害

    @__kokumoto

    28 Oct 2025

    778 Impressions

    0 Retweets

    3 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  13. CVE-2025-10680 OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell commands via DNS variables when --dns-updown is in … https://t.co/pVQSAjstCP

    @CVEnew

    24 Oct 2025

    313 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  1. Zephyr's WireGuard VPN data-plane receive handler wg_process_data_message() in subsys/net/lib/wireguard/wg_crypto.c validated the anti-replay counter too late. After AEAD decryption of a MESSAGE_TRANSPORT_DATA packet succeeded, the code committed several peer-state changes — update_peer_addr() (endpoint roaming update), the keypair->last_rx/peer->last_rx liveness timers, and keypair_update() (promote next→current and destroy the previous keypair) — and only afterward called wg_check_replay(). On a replayed packet the replay check returned -EINVAL, but none of the preceding mutations were rolled back. The AEAD tag authenticates content but not freshness, so a replayed-but-authentic transport packet decrypts correctly. An attacker who captures one valid ciphertext off the wire (an on-path or shared-medium observer) can re-inject it from an arbitrary spoofed source address. Reaching the handler requires no credentials: it is driven directly from inbound UDP datagrams via the dispatch in subsys/net/lib/wireguard/wg.c. Because the state mutations committed before the replay check, the replay repoints the peer endpoint to the attacker-chosen source address (roaming hijack), redirecting the victim's subsequent outbound tunnel traffic until the legitimate peer's next packet re-corrects it; it also prematurely destroys the previous keypair and refreshes the RX liveness timer. The tunnel payload stays encrypted under the session keypair, so this is an integrity/availability impact (traffic redirection and session disruption), not payload disclosure. The fix moves wg_check_replay() to immediately after a successful decrypt, before any peer-state mutation, matching the WireGuard specification and the Linux reference implementation.CVE-2026-13734