Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-24356

20
FAUCET Score

CVE-2025-24356 describes a UDP amplification vulnerability in fastd, a VPN daemon. This flaw allows an attacker to send small, spoofed UDP packets to fastd instances, triggering a significantly larger handshake response (amplification factor of 12-13x). With a CVSS score of 7.5 (High), this vulnerability poses a significant risk for Distributed Denial of Service (DDoS) attacks against targeted victims. While there is no evidence of active exploitation, public exploit code, or community discussion, the ease of exploitation (network attack vector, low complexity) warrants attention. A fix is available in fastd v23.

Impacted Technologies

VendorProductVersion(s)CPE
< 23.0CPE matchmatch criteria
cpe:2.3:a:fastd_project:fastd:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

6.9MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
LOW
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.65%
Probability of exploitation in next 30 days
EPSS Percentile
47.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0065 is in the 24th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / neocturne/fastd/commit/1f233bee76b722c0b3f9024f2c39c72e9f7e5843
Patch
github.com / neocturne/fastd/commit/3940150e801d0c91460491bec32cbcc5bbc89d5f
Patch
github.com / neocturne/fastd/commit/5f63fcfc18ae9cad023fa463b152d5e14192b5a8
Patch
github.com / neocturne/fastd/commit/9df7e516378441d2d17b89f9db5c27c8312d8f12
Patch
github.com / neocturne/fastd/commit/c1a07b3f2b9066c3713c68547da700b85d60f4f7
Patch
github.com / neocturne/fastd/commit/ce1b79b12dbfa796743b5f3a50789ade965b7023
Patch
github.com / neocturne/fastd/commit/d03a0a17347efb5293e42fde7d982781e90f14ef
Patch
github.com / neocturne/fastd/security/advisories/GHSA-pggg-vpfv-4rcv
MitigationPatchVendor Advisory