Forwarded from Taiwan Computer Emergency Response Team/Coordination Center Security Alert TWCERTCC-200-202601-00000001
[QNO | VPN Firewall - Insufficient Entropy] (CVE-2025-15387, CVSS: 8.8) An Insufficient Entropy vulnerability exists in VPN Firewalls. A remote unauthenticated attacker can obtain any logged-in user's session through brute force, thereby logging into the system.
[QNO | VPN Firewall - OS Command Injection] (CVE-2025-15388, CVSS: 8.8) An OS Command Injection vulnerability exists in VPN Firewalls. A remote authenticated attacker can inject arbitrary operating system commands and execute them on the server.
[QNO | VPN Firewall - OS Command Injection] (CVE-2025-15389, CVSS: 8.8) An OS Command Injection vulnerability exists in VPN Firewalls. A remote authenticated attacker can inject arbitrary operating system commands and execute them on the server.