CVE-2025-25568
CRITICALSoftEtherVPN 5.02.5187 - Use-After-Free in Command.c CheckNetworkAcceptThread
Title source: llmDescription
SoftEtherVPN 5.02.5187 is vulnerable to Use after Free in the Command.c file via the CheckNetworkAcceptThread function. NOTE: the Supplier disputes this because the use-after-free is not in the VPN software, but is instead in a separate tool that has no untrusted input and runs under the user's own privileges (it is a stress-testing tool for a networking stack).
References (2)
Core 2
Core References
Scores
CVSS v3
9.8
EPSS
0.0054
EPSS Percentile
41.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-416
Status
published
Products (1)
softether/vpn
5.02.5187
Published
Mar 12, 2025
Tracked Since
Feb 18, 2026