CVE-2025-11130

HIGH

iHongRen pptp-vpn 1.0/1.0.1 - Missing Authentication

Title source: llm
STIX 2.1

Description

A weakness has been identified in iHongRen pptp-vpn 1.0/1.0.1 on macOS. This issue affects the function shouldAcceptNewConnection of the file HelpTool/HelperTool.m of the component XPC Service. This manipulation causes missing authentication. The attack can only be executed locally. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.326210
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.326210
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.655456

Scores

CVSS v3 8.4
EPSS 0.0023
EPSS Percentile 13.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-287 CWE-306
Status published
Products (2)
iHongRen/pptp-vpn 1.0
iHongRen/pptp-vpn 1.0.1
Published Sep 29, 2025
Tracked Since Feb 18, 2026