Drooid Logo
Back to today’s briefing

Story perspectives

Critical VPN Vulnerability Discovered: Exploitation Risks Rise

4/15/2025

33 7

1 of 1

Story summary
  • A serious remote code execution vulnerability (CVE-2025-22457) was identified in Ivanti’s Connect Secure VPN, attributed to a Chinese threat actor group.
  • Rapid7 reverse-engineered the flaw, which was discreetly patched in February without adequate disclosure.
  • Attackers can exploit this vulnerability through the “X-Forwarded-For” header, leading to full remote code execution.
  • Patches are available for affected versions; organizations should monitor for potential web server crashes.