CVE-2025-66575

V

eeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute code during startup or reboot with escalated privileges. Attackers can exploit this by providing a malicious service name, allowing them to inject commands and run as LocalSystem.

Configurations

Configuration 1 (hide)

cpe:2.3:a:veepn:veepn:1.6.1:*:*:*:*:*:*:*

History

30 Dec 2025, 16:33

Type Values Removed Values Added
First Time Veepn veepn
Veepn
CPE cpe:2.3:a:veevpn:veevpn:1.6.1:*:*:*:*:*:*:* cpe:2.3:a:veepn:veepn:1.6.1:*:*:*:*:*:*:*

17 Dec 2025, 16:31

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-04 21:16

Updated : 2025-12-30 16:33


NVD link : CVE-2025-66575

Mitre link : CVE-2025-66575

CVE.ORG link : CVE-2025-66575


JSON object : View

Products Affected
CWE
CWE-428

Unquoted Search Path or Element