CVE-2025-25568

SoftEtherVPN 5.02.5187 is vulnerable to Use after Free in the Command.c file via the CheckNetworkAcceptThread function. NOTE: the Supplier disputes this because the use-after-free is not in the VPN software, but is instead in a separate tool that has no untrusted input and runs under the user's own privileges (it is a stress-testing tool for a networking stack).
Configurations

Configuration 1 (hide)

cpe:2.3:a:softether:vpn:5.02.5187:*:*:*:*:*:*:*

History

19 Jul 2025, 02:15

Type Values Removed Values Added
References
  • () https://filecenter.softether-upload.com/d/250715_001_79538/CVE-2025-25568.pdf -
Summary (en) SoftEtherVPN 5.02.5187 is vulnerable to Use after Free in the Command.c file via the CheckNetworkAcceptThread function. (en) SoftEtherVPN 5.02.5187 is vulnerable to Use after Free in the Command.c file via the CheckNetworkAcceptThread function. NOTE: the Supplier disputes this because the use-after-free is not in the VPN software, but is instead in a separate tool that has no untrusted input and runs under the user's own privileges (it is a stress-testing tool for a networking stack).

02 Apr 2025, 20:36

Type Values Removed Values Added
References () https://lzydry.github.io/CVE-2025-25568/ - () https://lzydry.github.io/CVE-2025-25568/ - Exploit
CPE cpe:2.3:a:softether:vpn:5.02.5187:*:*:*:*:*:*:*
First Time Softether
Softether vpn

19 Mar 2025, 19:15

Type Values Removed Values Added
CWE CWE-416
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
Summary
  • (es) SoftEtherVPN 5.02.5187 es vulnerable a uso después de la liberación en el archivo Command.c a través de la función CheckNetworkAcceptThread.
References () https://lzydry.github.io/CVE-2025-25568/ - () https://lzydry.github.io/CVE-2025-25568/ -

12 Mar 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-12 16:15

Updated : 2025-07-19 02:15


NVD link : CVE-2025-25568

Mitre link : CVE-2025-25568

CVE.ORG link : CVE-2025-25568


JSON object : View

Products Affected

softether

  • vpn
CWE
CWE-416

Use After Free