- Description
- FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common Name and DNS SAN string matching instead of using OpenSSL's length-aware identity validation APIs, it (1) truncates DNS SAN values at embedded NUL bytes (accepting e.g. 'victim.example\0.attacker.example' as 'victim.example'), (2) accepts a matching Common Name even when non-matching DNS SAN entries are present, and (3) accepts IP-literal targets via DNS/CN matching without comparing iPAddress SANs. Under a trusted or misissued certificate chain, an attacker positioned to present such a certificate can bypass server identity verification, weakening TLS server authentication.
- Source
- disclosure@vulncheck.com
- NVD status
- Received
CVSS 4.0
- Type
- Secondary
- Base score
- 9.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- disclosure@vulncheck.com
- CWE-295
- Hype score
- Not currently trending
Critical zero-days: SonicWall SMA 1000 (CVE-2026-15409/10) exploited by ransomware & FreeRDP TLS bypass (CVE-2026-66402) found. Immediate patching vital to safeguard data privacy/integrity in transit. #Cybersecurity #News
@YourAnon_irc
4 Aug 2026
88 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
π #CyberSecurity CVE-2026-66402: Critical OpenSSL Remote Execution β Detection & Hardening "A critical vulnerability has been identified in OpenSSL, designated CVE-2026-66402. This flawβ¦" π https://t.co/48KNVO5D4X #CyberSecurity #ThreatIntel #cve202666402 #criti
@SecurityAr58409
1 Aug 2026
44 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
π¨Critical - Two FreeRDP client flaws: TLS cert-validation bypass and HTTP proxy request injection (CVE-2026-66402 & CVE-2026-67289) Both affect FreeRDP <= 3.28.0 and are fixed in 3.29.0. CVE-2026-66402 (CWE-295): FreeRDP does custom CN/DNS-SAN matching instead of Open
@UpwindMDR
1 Aug 2026
94 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes