security1 distinct publisher
A CRLF injection in IXON's VPN client gives unauthenticated callers root that survives reboot
CVE-2026-75925 lets anything that reaches the client's local configuration interface plant directives in a file a privileged subprocess later runs. Since 5 August 2026 IXON's cloud has refused clients below 1.4.7, which is what actually breaks the chain.
Publishers:cisa.gov
Reality
- Evidence68
- Adoption40
- Hype gap−10
- Incentives58