CVE-2025-25565 Details
Description
SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in the Command.c file via the PtMakeCert and PtMakeCert2048 functions. NOTE: the Supplier disputes this because the behavior only allows a user to attack himself by typing a long string on a command line.
A buffer overflow vulnerability has been identified in SoftEther VPN version 5.02.5187. The issue arises in the Command.c file within the PtMakeCert and PtMakeCert2048 functions. These functions, part of the VPN Tools menu, handle certificate creation but improperly manage input for the expiration date, allowing for overflow at 137 bytes.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| softether vpn | 5.02.5187 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 19, 2025 | CVE Modified | [email protected] |
| Apr 2, 2025 | Initial Analysis | [email protected] |
| Mar 19, 2025 | CVE Modified | CISA-ADP |
| Mar 12, 2025 | New CVE Received | [email protected] |