Home

Description

NextVPN 4.10 contains an insecure file permissions vulnerability that allows local users to modify executable files with full access rights. Attackers can replace system executables with malicious files to gain SYSTEM or Administrator privileges through unauthorized file modification.

PUBLISHED Reserved 2026-02-12 | Published 2026-02-12 | Updated 2026-02-12 | Assigner VulnCheck




HIGH: 8.5CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

Incorrect Permission Assignment for Critical Resource

Product status

4.10
affected

Credits

SajjadBnd finder

References

www.exploit-db.com/exploits/47831 (ExploitDB-47831) exploit

vm3max.site (Vendor Homepage) product

www.vulncheck.com/...ories/nextvpn-insecure-file-permissions (VulnCheck Advisory: NextVPN v4.10 - Insecure File Permissions) third-party-advisory

cve.org (CVE-2019-25343)

nvd.nist.gov (CVE-2019-25343)

Download JSON