CVE-2025-13086 is a high-severity vulnerability affecting OpenVPN versions 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1, stemming from improper validation of source IP addresses. This flaw allows an unauthenticated attacker to hijack an existing OpenVPN session from a different IP address, leading to a denial of service for the legitimate client. With a CVSS score of 7.5, the vulnerability is network-exploitable with low attack complexity and no user interaction required, resulting in high availability impact. There is currently no evidence of active exploitation, nor are there public exploit modules like Metasploit or Nuclei, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.0, < 2.6.16CPE matchmatch criteria | cpe:2.3:a:openvpn:openvpn:*:*:*:*:community:*:*:* | ||
2.7CPE matchmatch criteria | cpe:2.3:a:openvpn:openvpn:2.7:alpha1:*:*:community:*:*:* | ||
2.7CPE matchmatch criteria | cpe:2.3:a:openvpn:openvpn:2.7:alpha2:*:*:community:*:*:* | ||
2.7CPE matchmatch criteria | cpe:2.3:a:openvpn:openvpn:2.7:alpha3:*:*:community:*:*:* | ||
2.7CPE matchmatch criteria | cpe:2.3:a:openvpn:openvpn:2.7:beta1:*:*:community:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.