Description
Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending sequences being neutralized, which allows additional directives to be introduced into that file. The configuration interface accepts changes without authenticating or verifying the origin of the requester. The injected configuration persists on disk across restarts of the client and the operating system, and the VPN connection continues to function normally, so there is no behavioral change visible to the user.
Published: 2026-09-04
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The IXON VPN Client before version 1.4.7 fails to neutralize CRLF sequences in configuration data that is later consumed by a privileged subprocess. An attacker can supply configuration changes without authenticating the source, leading to injected directives that execute arbitrary commands as root or SYSTEM. The exploit does not alter the visual behavior of the VPN connection, so the user sees no apparent change.

Affected Systems

The affected product is IXON VPN Client. Any installation of IXON VPN Client older than version 1.4.7 is vulnerable. The client has been configured to reject connections from versions below 1.4.7, preventing the exploit chain from completing, but unpatched clients remain at risk.

Risk and Exploitability

With a CVSS score of 9.4 the vulnerability is high severity. No EPSS score is available and it is not listed in the CISA KEV catalog, but the attack would require delivery of a crafted configuration change to the client, which is plausible in environments where the client can be remotely accessed or where a local attacker can modify configuration files. The privileged subprocess runs with system-level rights, making the impact of successful exploitation catastrophic.

Generated by OpenCVE AI on September 4, 2026 at 22:21 UTC.

Remediation

Vendor Solution

IXON recommends updating the IXON VPN client to version 1.4.7 or later on every computer where it is installed. As of August 5, 2026, IXON cloud rejects connections from clients below v1.4.7 at both the portal and the back-end API. Since the privileged subprocess and injected listener are only created when the client connects, unpatched installations cannot complete the exploit chain. If the client is no longer needed, IXON recommends uninstalling the VPN client from the computer. For more information please refer to the IXON Trust Center Advisory at:  https://www.ixon.cloud/Advisories/ADV-2026-08-05.pdf https://www.ixon.cloud/Advisories/ADV-2026-08-05.pdf%60


OpenCVE Recommended Actions

  • Update the IXON VPN client to version 1.4.7 or later, which removes the CRLF injection flaw
  • If the VPN client is no longer needed, uninstall it from the computer to eliminate the attack surface
  • Verify that any required VPN functionality is preserved after the update or removal, and monitor client systems for unexpected configuration changes

Generated by OpenCVE AI on September 4, 2026 at 22:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending sequences being neutralized, which allows additional directives to be introduced into that file. The configuration interface accepts changes without authenticating or verifying the origin of the requester. The injected configuration persists on disk across restarts of the client and the operating system, and the VPN connection continues to function normally, so there is no behavioral change visible to the user.
Title IXON VPN Client CRLF Injection
Weaknesses CWE-93
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-04T21:19:02.213Z

Reserved: 2026-08-18T15:31:34.250Z

Link: CVE-2026-75925

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T22:17:18.017

Modified: 2026-09-04T22:17:18.017

Link: CVE-2026-75925

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T22:30:07Z

Weaknesses
  • CWE-93

    Improper Neutralization of CRLF Sequences ('CRLF Injection')