CVE-2026-25998 is a critical vulnerability in strongMan, the management interface for strongSwan VPN, affecting versions prior to 0.2.0. It stems from improper encryption of stored credentials, where a global key and non-unique initialization vectors (IVs) were used, leading to the reuse of encryption key streams. An attacker with database access can exploit this flaw to decrypt sensitive information like private keys and EAP secrets by leveraging publicly available encrypted certificates. The vulnerability carries a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity and high confidentiality impact, requiring no user interaction or privileges. The primary impact is the complete compromise of stored credentials. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.1.0CPE matchmatch criteria | cpe:2.3:a:strongswan:strongman:0.1.0:*:*:*:*:python:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.