CVE-2023-27516
An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. A specially crafted network packet can lead to unauthorized access. An attacker can send a network request to trigger this vulnerability.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.3
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
- EPSS probability
- 0.05%
- CWE
- CWE-453
- Published
- 2023-10-12
- Last modified
- 2026-03-13
Affected products
- SoftEther VPN SoftEther VPN
- SoftEther VPN SoftEther VPN
Weakness type
Related vulnerabilities
- CVE-2026-19212 — WonderTrader TraderATP Cash Trade Conversion WTSTradeDef.hpp uninitialized variable
- CVE-2026-41330 — OpenClaw < 2026.3.31 - Environment Variable Override via Host Exec Policy
- CVE-2025-61926 — Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret
- CVE-2025-47945 — Donetick Has Weak Default JWT Secret
- CVE-2025-30206 — Dpanel's hard-coded JWT secret leads to remote code execution
- CVE-2024-49120 — Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2024-39916 — NFS server misconfiguration allows file access outside the exported directory
- CVE-2024-21411 — Skype for Consumer Remote Code Execution Vulnerability