IM
IronMonkey Threat Research
‹ Back to ICS Advisories

IXON VPN Client

CRITICAL
CVSS 9.6
Date 2026-09-03T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-75925 9.6 critical
Improper Neutralization of CRLF Sequences (CWE-93) in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending sequences being neutralised, which allows additional directives to be introduced into that file. The configuration interface accepts changes without authenticating or verifying the origin of the requester (CWE-306, contributing). The injected configuration persists on disk across restarts of the client and the operating system, and the VPN connection continues to function normally, so there is no behavioral change visible to the user.

// Remediations (4)

Mitigation: For more information please refer to the IXON Trust Center Advisory at https://www.ixon.cloud/Adviso
For more information please refer to the IXON Trust Center Advisory at https://www.ixon.cloud/Advisories/ADV-2026-08-05.pdf.
Mitigation: If the client is no longer needed, IXON recommends uninstalling the VPN client from the computer.
If the client is no longer needed, IXON recommends uninstalling the VPN client from the computer.
Mitigation: As of August 5, 2026, IXON cloud rejects connections from clients below v1.4.7 at both the portal an
As of August 5, 2026, IXON cloud rejects connections from clients below v1.4.7 at both the portal and the back-end API. Since the privileged subprocess and injected listener are only created when the client connects, unpatched installations cannot complete the exploit chain.
Mitigation: IXON recommends updating the IXON VPN client to version 1.4.7 or later on every computer where it is
IXON recommends updating the IXON VPN client to version 1.4.7 or later on every computer where it is installed.

// References