216.73.216.36

CVE-2025-59692

· Published 18/09/2025 23:15 · Modified 19/09/2025 16:00

Labels: CVE-2025-59692 2025-09-18CVE-2025-59692CWE-669[email protected]

Essential information

Published
18/09/2025 23:15
Modified
19/09/2025 16:00
Author
Creator
CVSS
3.7 LOW (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

CVSS metrics

Description

PureVPN client applications on Linux through September 2025 mishandle firewalling. They flush the system's existing iptables rules and apply default ACCEPT policies when connecting to a VPN server. This removes firewall rules that may have been configured manually or by other software (e.g., UFW, container engines, or system security policies). Upon VPN disconnect, the original firewall state is not restored. As a result, the system may become unintentionally exposed to network traffic that was previously blocked. This affects CLI 2.0.1 and GUI 2.10.0.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
purevpn / purevpn cli cpe:2.3:a:purevpn:purevpn_cli:2.0.1:*:*:*:*:*:*:*
purevpn / purevpn gui cpe:2.3:a:purevpn:purevpn_gui:2.10.0:*:*:*:*:*:*:*

References