Major new online tunnel vulnerability could put millions of devices at risk


  • Security researchers find multiple vulnerabilities in different tunneling protocols
  • Bugs allowed threat actors to mount DoS attacks and more
  • Most of the vulnerable endpoints were in China.

Millions of VPN servers, home routers and other Internet hosts could have multiple vulnerabilities that could allow threat actors to conduct anonymous attacks and grant them access to private networks, experts warned.

New research by Mathy Vanhoef, professor at KU Leuven University in Belgium, PhD student Angelos Beitis and Top10VPN discovered the vulnerabilities in multiple tunneling protocols: IPIP/IP6IP6, GRE/GRE6, 4in6, and 6in4, and received these identifiers: CVE-2024-7595, CVE-2025-23018, CVE-2025-23019, and CVE-2024-7596.

Leave a Comment

Your email address will not be published. Required fields are marked *