Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-13086

26
FAUCET Score

CVE-2025-13086 is a high-severity vulnerability affecting OpenVPN versions 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1, stemming from improper validation of source IP addresses. This flaw allows an unauthenticated attacker to hijack an existing OpenVPN session from a different IP address, leading to a denial of service for the legitimate client. With a CVSS score of 7.5, the vulnerability is network-exploitable with low attack complexity and no user interaction required, resulting in high availability impact. There is currently no evidence of active exploitation, nor are there public exploit modules like Metasploit or Nuclei, though it has garnered some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.0, < 2.6.16CPE matchmatch criteria
cpe:2.3:a:openvpn:openvpn:*:*:*:*:community:*:*:*
2.7CPE matchmatch criteria
cpe:2.3:a:openvpn:openvpn:2.7:alpha1:*:*:community:*:*:*
2.7CPE matchmatch criteria
cpe:2.3:a:openvpn:openvpn:2.7:alpha2:*:*:community:*:*:*
2.7CPE matchmatch criteria
cpe:2.3:a:openvpn:openvpn:2.7:alpha3:*:*:community:*:*:*
2.7CPE matchmatch criteria
cpe:2.3:a:openvpn:openvpn:2.7:beta1:*:*:community:*:*:*

CVSS Data

CVSS version used by this source: 4.0

4.6MEDIUM

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
UNREPORTED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.64%
Probability of exploitation in next 30 days
EPSS Percentile
46.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0063 is in the 23rd percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

oroincpatch availablevia llm_extracted
Fixed in: 3.0.2
View patch

Vendor Advisories (2)

redhatCVE-2025-13086Moderate

OpenVPN: OpenVPN: Improper validation of source IP addresses leads to denial of service

Dec 3, 2025
oroincllm-oroinc-42b0d2d8a6622bf1MEDIUM

Remote Denial-of-Service (DoS) in OpenVPN Access Server

Dec 1, 2025

References

community.openvpn.net / Security%20Announcements/CVE-2025-13086
Vendor Advisory
mail-archive.com / [email protected]/msg00151.html
Mailing ListRelease Notes
mail-archive.com / [email protected]/msg00152.html
Mailing ListRelease Notes