CVE-2025-25567

SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in Internat.c via the UniToStrForSingleChars function. NOTE: the Supplier disputes this because the behavior only enables a local user to attack himself through the UI,
Configurations

Configuration 1 (hide)

cpe:2.3:a:softether:vpn:5.02.5187:*:*:*:*:*:*:*

History

19 Jul 2025, 02:15

Type Values Removed Values Added
Summary (en) SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in Internat.c via the UniToStrForSingleChars function. (en) SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in Internat.c via the UniToStrForSingleChars function. NOTE: the Supplier disputes this because the behavior only enables a local user to attack himself through the UI,
References
  • () https://filecenter.softether-upload.com/d/250715_001_79538/CVE-2025-25567.pdf -

02 Apr 2025, 20:36

Type Values Removed Values Added
References () https://lzydry.github.io/CVE-2025-25567/ - () https://lzydry.github.io/CVE-2025-25567/ - Exploit
CPE cpe:2.3:a:softether:vpn:5.02.5187:*:*:*:*:*:*:*
First Time Softether
Softether vpn

19 Mar 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://lzydry.github.io/CVE-2025-25567/ - () https://lzydry.github.io/CVE-2025-25567/ -
Summary
  • (es) SoftEther VPN 5.02.5187 es vulnerable al desbordamiento del búfer en Internat.c a través de la función UniToStrForSingleChars.
CWE CWE-120

12 Mar 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-12 16:15

Updated : 2025-07-19 02:15


NVD link : CVE-2025-25567

Mitre link : CVE-2025-25567

CVE.ORG link : CVE-2025-25567


JSON object : View

Products Affected

softether

  • vpn
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')