CVE-2026-39312 is a pre-authentication denial-of-service vulnerability affecting SoftEtherVPN Developer Edition version 5.2.5188 and earlier. An unauthenticated remote attacker can crash the vpnserver process by transmitting a single malformed EAP-TLS packet over raw L2TP protocol on UDP port 1701, resulting in termination of all active VPN sessions and service disruption. The vulnerability carries a CVSS score of 7.5 (HIGH) with a network-based attack vector requiring no authentication or user interaction. The attack has low complexity, making it easily exploitable by remote threat actors. The impact is limited to availability, as the vulnerability does not compromise confidentiality or integrity of data. Current exploitation status indicates low community attention and no active exploitation in the wild. The EPSS score of 0.0025 suggests minimal likelihood of exploitation compared to other known vulnerabilities. Notably, this vulnerability does not appear on the CISA Known Exploited Vulnerabilities list and is classified as inactive on threat tracking platforms, indicating it has not become a priority target for threat actors despite its technical exploitability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.2.5188CPE matchmatch criteria | cpe:2.3:a:softether:softethervpn:*:*:*:*:developer:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.