A denial-of-service vulnerability exists in the vpnserver ConnectionAccept() functionality of SoftEther VPN 5.02. A set of specially crafted network connections can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HSoftether Vpn
APPSoftether5.02
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoSVPN
Related vulnerabilities
CVE-2025-25565CRITICAL9.8PL ✓same product
Buffer Overflow w SoftEther VPN – funkcje PtMakeCert i PtMakeCert2048
CVE-2025-25568CRITICAL9.8PL ✓same product
Use-after-free w SoftEther VPN 5.02.5187 – Command.c (CheckNetworkAcceptThread)
CVE-2025-25567CRITICAL9.8PL ✓same product
Buffer overflow w SoftEther VPN – funkcja UniToStrForSingleChars
CVE-2023-27395CRITICAL9.0PL ✓same product
Heap-based buffer overflow w SoftEther VPN umożliwiający RCE
CVE-2023-23581HIGH7.5same product
A denial-of-service vulnerability exists in the vpnserver EnSafeHttpHeaderValueStr functionality of SoftEther ...