Impact
NetworkManager-l2tp is vulnerable due to improper input validation that permits local users who can create VPN connections to inject arbitrary pppd directives. By supplying mru or mtu values that contain a valid integer followed by non‑numeric characters, the application writes the unvalidated string directly into the pppd options file. This enables an attacker to add a plugin directive that loads an attacker‑controlled shared object, resulting in arbitrary code execution as root. The vulnerability is classified as CWE‑88.
Affected Systems
The affected product is NetworkManager-l2tp. Versions 1.52.4 and earlier are vulnerable. Versions 1.52.6 and later include the fix. Users should verify their installed version. If an installation relies on the default l2tp plugin, it could be affected.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity assessment. EPSS is reported as less than 1%, implying a currently low probability of exploitation in the wild, and the issue is not listed in the CISA KEV catalog. However, the attack vector remains local; an authenticated user with VPN creation privileges can launch the exploit without network access. If executed, the attacker achieves full root privileges on the host.
OpenCVE Enrichment
Debian DLA