CVE-2025-64125 describes a critical Network Boundary Bridging vulnerability in Nuvation Energy's nCloud VPN Service. This flaw, rated 9.4 CRITICAL, allows a low-privileged attacker with user interaction to achieve high confidentiality, integrity, and availability impacts across multiple security scopes. While no active exploits or public exploit code are currently known, and community discussion is minimal, the high FAUCET Risk Score of 91/100 indicates significant potential danger. The issue was fixed on December 1, 2025, requiring no end-user action for mitigation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Nuvation Energy | NCloud VPN Service | 2025-12-1CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.6 Bluesky, 0.3 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.