Back to search
CVE-2025-10680
Published: Oct 24, 2025
Modified: Feb 26, 2026
PUBLISHED
Description
OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell commands via DNS variables when --dns-updown is in use
| Vendor | Product | Versions |
|---|---|---|
OpenVPN | OpenVPN | affected 2.7_alpha1 - <= 2.7_beta1 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now