PoC public strongSwan ddos-botnet network-edge
strongSwan CVE-2026-25075: Integer Underflow in VPN Authentication
TL;DR
Bishop Fox researchers took a deep dive into a new strongSwan vulnerability that allows unauthenticated attackers to take VPN services offline, with the bug impacting versions going back over 15 years. Exposure is likely anywhere EAP-TTLS is enabled. We created an easy tool to test your strongSwan deployment & recommend upgrading to version 6.0.5 and later.…