ZeroHour

CVE-2026-75925

niche

CRLF Injection in IXON VPN Client Enables Root/SYSTEM Command Execution

CVSS 4.0
9.4 critical
EPSS
<1%p50
Published
()
Modified
AI analysis

CVE-2026-75925 is a CRLF injection flaw (CWE-93) in the IXON VPN Client prior to version 1.4.7, where configuration values accepted by the local service are written to a file that is later consumed by a privileged subprocess without line-ending sequences being neutralized. Because the configuration interface accepts changes without authenticating or verifying the requester, a remote attacker (with some user interaction per the CVSS vector) can submit crafted configuration values that inject additional directives into the privileged file. This allows the attacker to execute commands with root (Linux) or SYSTEM (Windows) privileges on the machine running the client. The injected configuration persists silently across restarts of the client and the operating system, and the VPN continues to work normally, so victims see no visible change. No public proof-of-concept, KEV listing, or reported in-the-wild exploitation is known; EPSS currently estimates a 0.7% chance of exploitation within 30 days.

What to do: Upgrade IXON VPN Client to version 1.4.7 or later on all Windows and Linux hosts. Because injected configuration values persist silently on disk, after patching inspect the client's configuration file for unexpected extra directives and rewrite it with known-good values. Until patched, limit exposure of the local configuration interface (e.g., avoid untrusted browsing on privileged support workstations) and monitor for the vendor's advisory and any published proof-of-concept.

Affected
IXON VPN Clientall versions before 1.4.7
Estimated exposure
nichelikely on the order of tens of thousands of installations worldwide (industrial remote-access niche vendor; no public install counts in the provided data) — IXON's VPN Client is deployed mainly on technician and support workstations for industrial remote maintenance, a niche market without published install counts, so this order-of-magnitude estimate is a deployment-pattern-based guess rather…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending sequences being neutralized, which allows additional directives to be introduced into that file. The configuration interface accepts changes without authenticating or verifying the origin of the requester. The injected configuration persists on disk across restarts of the client and the operating system, and the VPN connection continues to function normally, so there is no behavioral change visible to the user.

Weakness
CWE-93
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

IXON VPN Client

CISA warns CVE-2026-75925 (CVSS 9.6) in IXON VPN Client <1.4.7 lets attackers inject config directives for root/SYSTEM remote code execution.

IXON's CRLF injection flaw (CVE-2026-75925, CWE-93) in VPN Client before 1.4.7 lets the unauthenticated local configuration service inject additional directives into a file consumed by a privileged subprocess. Injected configuration persists across client and OS restarts, enabling code execution as root or SYSTEM while the VPN connection keeps functioning normally. Deployments span energy, manufacturing, water, and IT sectors; no public exploitation has been reported to CISA.

CISA Advisories · 12d agoAdvisoryCVE-2026-75925