Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-75925: IXON VPN Client lets attackers run code as admin

CVE-2026-75925 · published today
Summary

The IXON VPN client (versions before 1.4.7) can be tricked into adding extra commands to its own configuration file. Because the client does not check who is making changes, an attacker could insert commands that run with the highest system privileges, and the changes remain even after a restart. Update the client to the latest version or reinstall it to eliminate this risk.

What to do
  • Update ixon ixon vpn client to version 1.4.7 or later.
Affected software
VendorProductAffected versions
ixon ixon vpn client < 1.4.7
Original advisory text
IXON VPN Client CRLF Injection
Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending sequences being neutralized, which allows additional directives to be introduced into that file. The configuration interface accepts changes without authenticating or verifying the origin of the requester. The injected configuration persists on disk across restarts of the client and the operating system, and the VPN connection continues to function normally, so there is no behavioral change visible to the user.
Severity
9.4 Critical
CVSS 3.1: 9.6 (NVD)
CVSS 4.0: 9.4 (NVD)
Type
CWE-93Improper Neutralization of CRLF Sequences ('CRLF Injection')
Timeline
Published4 Sep 2026
Updated4 Sep 2026
First seen4 Sep 2026
Sources
CVE-2026-75925 · MITRE
Monitor software like this
Free during beta