CVE-2025-59692
Last modified
CVE-2025-59692 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. PureVPN client applications on Linux through September 2025 mishandle firewalling. They flush the system's existing iptables rules and apply default ACCEPT policies when connecting to a VPN server. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
PureVPN client applications on Linux through September 2025 mishandle firewalling. They flush the system's existing iptables rules and apply default ACCEPT policies when connecting to a VPN server. This removes firewall rules that may have been configured manually or by other software (e.g., UFW, container engines, or system security policies). Upon VPN disconnect, the original firewall state is not restored. As a result, the system may become unintentionally exposed to network traffic that was previously blocked. This affects CLI 2.0.1 and GUI 2.10.0.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-59692?
How severe is CVE-2025-59692?
How do I fix CVE-2025-59692?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-59685Kazaar 1.25.12 allows a JWT with none in the alg field.5.3
- CVE-2025-59686Kazaar 1.25.12 allows /api/v1/org-id/orders/order-id/documen…6.5
- CVE-2025-59687IMPAQTR Aurora before 1.36 allows Insecure Direct Object Ref…4.3
- CVE-2025-59689Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command …6.1
- CVE-2025-5969A vulnerability has been found in D-Link DIR-632 FW103B08 an…8.8
- CVE-2025-59691PureVPN client applications on Linux through September 2025 …3.7
- CVE-2025-59693The Chassis Management Board in Entrust nShield Connect XC, …9.8
- CVE-2025-59694The Chassis Management Board in Entrust nShield Connect XC, …6.8
- CVE-2025-59695Entrust nShield Connect XC, nShield 5c, and nShield HSMi thr…9.8
- CVE-2025-59696Entrust nShield Connect XC, nShield 5c, and nShield HSMi thr…3.2
- CVE-2025-59697Entrust nShield Connect XC, nShield 5c, and nShield HSMi thr…7.2
- CVE-2025-59698Entrust nShield Connect XC, nShield 5c, and nShield HSMi thr…6.8
Are you affected by CVE-2025-59692?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
