CVE-2025-25565 is a critical buffer overflow vulnerability (CWE-120) affecting SoftEther VPN version 5.02.5187, specifically within the PtMakeCert and PtMakeCert2048 functions in Command.c. This flaw carries a CVSSv3.1 score of 9.8, indicating a network-exploitable vulnerability with low attack complexity and high impact on confidentiality, integrity, and availability. Despite its critical severity, the vendor disputes the practical exploitability, stating it only allows self-inflicted denial of service. Currently, there is no public exploit code (Metasploit, Nuclei, ExploitDB) and no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.02.5187CPE matchmatch criteria | cpe:2.3:a:softether:vpn:5.02.5187:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.