8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell commands via DNS variables when --dns-updown is in use
AI Analysis
Remote authenticated server can inject shell commands via DNS variables
Basic Information
ID
CVE-2025-10680
Source
OpenVPN
Published
Oct 24, 2025 at 10:06
Modified
Oct 24, 2025 at 12:08
Affected Product
Vendor
OpenVPN
Product
OpenVPN
Version
2.7_alpha1
Affected Versions
OpenVPN OpenVPN 2.7_alpha1
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
OpenVPN
Product
OpenVPN
Version
2.7_alpha1, 2.7_beta1