DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:LApple iOS
OSAppleall versionsApple macOS
OSAppleall versionsCisco Anyconnect Vpn Client
APPCiscoall versionsCisco Secure Client
APPCiscoall versionsCitrix Secure Access Client
APPCitrix< 24.8.5< 24.06.1F5 Big Ip Access Policy Manager
APPF57.2.3 – 7.2.517.1.0 – 17.1.215.1.0 – 15.1.1016.1.0 – 16.1.5Fortinet Forticlient
APPFortinet7.4.06.4.0 – 7.2.5 (excl.)Linux Kernel
OSLinuxall versionsPalo Alto Networks Globalprotect
APPPaloaltonetworksall versionsWatchguard Ipsec Mobile Vpn Client
APPWatchguardall versionsWatchguard Mobile Vpn With Ssl
APPWatchguardall versionsZscaler Client Connector
APPZscaler< 1.5.1.25< 4.2.0.2823.7 – 3.7.0.134 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
VPN
References
Related vulnerabilities
CVE-2026-65400CRITICAL9.8⚠ KEVPL ✓same product
Pominięcie uwierzytelniania w Screen Sharing na macOS
CVE-2025-53521CRITICAL9.3⚠ KEVPL ✓same product
RCE w F5 BIG-IP APM poprzez złośliwy ruch sieciowy (stack buffer overflow)
CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product
Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu
CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP