CVE-2026-25075 is an integer underflow vulnerability affecting strongSwan versions 4.5.0 prior to 6.0.5, specifically within the EAP-TTLS AVP parser due to insufficient validation of AVP length fields. This high-severity (CVSS 7.5) flaw allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data during IKEv2 authentication, potentially leading to excessive memory allocation or NULL pointer dereference and crashing the charon IKE daemon. There is currently no evidence of active exploitation, nor are public exploit codes available on platforms like Metasploit or ExploitDB, though the vulnerability has received community discussion and vendor attention, including security updates from SUSE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.5.0, < 6.0.5CPE match | cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.