IXON VPN Client
A critical vulnerability (CVE-2026-75925) exists in the IXON VPN Client, version 1.4.6 and earlier, allowing an attacker to execute commands as root or SYSTEM. This is due to improper neutralization of CRLF sequences, enabling injection of malicious configuration data. The vulnerability can be exploited without any visible behavioral changes to the user, and IXON has implemented mitigations including rejecting connections from older clients and recommending uninstalling the client.
A critical vulnerability (CVE-2026-75925) exists in the IXON VPN Client, version 1.4.6 and earlier, allowing an attacker to execute commands as root or SYSTEM. This is due to improper neutralization of CRLF sequences, enabling injection of malicious configuration data. The vulnerability can be exploited without any visible behavioral changes to the user, and IXON has implemented mitigations including rejecting connections from older clients and recommending uninstalling the client. The vulnerability stems from the client accepting configuration values without authenticating or verifying the origin of the requester (CWE-306, contributing). The injected configuration persists on disk across restarts of the client and the operating system, and the VPN connection continues to function normally, so there is no behavioral change visible to the user. The IXON Trust Center Advisory details the vulnerability and recommended mitigations. Luuk van Rheden of IXON discovered this vulnerability, and Stan van Duijnhoven of IXON reported it to CISA. CISA recommends users take defensive measures to minimize the risk of exploitation, including minimizing network exposure for control system devices, locating control system networks behind firewalls, and using more secure remote access methods like VPNs (updated to the latest version).