Major new online tunneling vulnerability could put millions of devices at risk


  • Security researchers discover multiple vulnerabilities in different tunneling protocols
  • The bugs allowed threat actors to launch DoS attacks and more.
  • Majority of vulnerable endpoints were in China

Millions of VPN servers, home routers and other Internet hosts could have multiple vulnerabilities that could allow malicious actors to carry out anonymous attacks and give them access to private networks, experts have warned.

New research from Mathy Vanhoef, professor at KU Leuven University in Belgium, doctoral student Angelos Beitis and Top10VPN discovered vulnerabilities in several tunneling protocols: IPIP/IP6IP6, GRE/GRE6, 4in6 and 6in4, and received these identifiers: CVE-2024-7595, CVE-2025-23018, CVE-2025-23019 and CVE-2024- 7596.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top