strongSwan CVE-2026-25075: Integer Underflow in VPN Authentication
bishopfox.com | vulnerability | High | CVE-2026-25075 | #vulnerability-research | #denial-of-service | #integer-underflow | #vpn | #strongswan | #cve-2026-25075 | #eap-ttls
Summary
Bishop Fox exploited CVE-2026-25075, an integer underflow in strongSwan's EAP-TTLS plugin (4.5.0-6.0.4): crafted messages crash the IKE daemon via two-phase heap corruption; upgrade to 6.0.5+.
- CVSS
- 7.5
- Published
- Collected
Skip to content