Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pritunl

First CVE: Jul 21, 2020Active for: 6 yearsTotal CVEs: 7

Pritunl provides a focused VPN and network access platform centered around its client and server applications, where the exposure concentrates in the Pritunl Client across desktop and electron-based deployments. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, recalling through weakness classes including improper privilege management, path traversal, link-following flaws, cryptographic signature validation issues, and observable discrepancies that reflect the trust and file-access control demands of client-side VPN software. Defenders should treat Pritunl Client updates as a priority where it is deployed for remote access; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pritunl over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 21, 2020
6 years ago
Most Recent CVE
Apr 19, 2025
462 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-25200MEDIUM
Pritunl 1.29.2145.25 allows attackers to enumerate valid VPN usernames via a series of /auth/session login attempts. Initially, the server will return error 401. However, if the us
Oct 1, 20205.331NOYES
CVE-2016-7063CRITICAL
A flaw was found in pritunl-client before version 1.0.1116.6. Arbitrary write to user specified path may lead to privilege escalation.
Jul 21, 20209.831NONO
CVE-2022-25372HIGH
Pritunl Client through 1.2.3019.52 on Windows allows local privilege escalation, related to an ACL entry for CREATOR OWNER in platform_windows.go.
Feb 20, 20227.825NONO
CVE-2016-7064HIGH
A flaw was found in pritunl-client before version 1.0.1116.6. A lack of signature verification leads to sensitive information leakage
Jul 21, 20207.525NONO
CVE-2020-27519HIGH
Pritunl Client v1.2.2550.20 contains a local privilege escalation vulnerability in the pritunl-service component. The attack vector is: malicious openvpn config. A local attacker c
Apr 30, 20217.823NONO
CVE-2025-43917HIGH
In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninstalling the product. Specifically, an administrator can inser
Apr 19, 20258.220NONO
CVE-2020-25989HIGH
Privilege escalation via arbitrary file write in pritunl electron client 1.0.1116.6 through v1.2.2550.20. Successful exploitation of the issue may allow an attacker to execute code
Nov 19, 20207.820NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
14%
71%
14%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (57.1%)
Network3 (42.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (42.9%)
High1 (14.3%)
None3 (42.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
14.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pritunl.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pritunl — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pritunl's Products

View all 2 CNAs →

Top CWEs