#VU118819 Insufficient verification of data authenticity in OpenVPN Server - CVE-2025-13086
Published: November 27, 2025
OpenVPN Server
OpenVPN
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to improper handling of HMAC verification checks during the three way handshake. A remote attacker can bypass source IP address validation and connect to the server from an IP address that did not initiate the initial connection.