Tec Nikan
فارسی
Talk to us
All news

A Remote Access Client With a Path to Root

CVE-2026-75925 scores 9.6: unauthenticated config injection in the IXON VPN client runs code as root or SYSTEM on the engineering laptop, and persists across restarts.

OT securityremote accessvulnerabilitiesengineering workstationsICS advisories

CISA's advisory ICSA-26-246-02 covers the IXON VPN Client, and the affected machines are the ones that should worry people most. The vulnerability, CVE-2026-75925, is CWE-93 — improper neutralisation of CRLF sequences — scoring 9.6 on CVSS v3.1 and 9.4 on v4.0. All versions before 1.4.7 are affected.

The mechanism is a configuration interface that does not verify authentication combined with line endings that are not neutralised, which lets an attacker inject unauthorised configuration directives. Those directives are consumed by a privileged process, producing remote code execution with elevated privileges — root or SYSTEM — on the computer running the client. The injected settings persist across restarts, so this is not a transient compromise.

The reason this outranks most controller vulnerabilities in practical terms is the machine it lands on. Remote access clients run on engineering laptops, and engineering laptops are the least protected and most privileged devices in the whole industrial estate. They hold PLC project files, drive parameter sets, HMI projects and safety configurations. They carry vendor credentials and site VPN profiles. They travel between the corporate network, the plant network and whatever hotel wifi the commissioning engineer was on last week, and they are frequently exempted from corporate endpoint policy because the engineering software will not run under it. A path to SYSTEM on that machine is a path to every site it has ever connected to.

The remediation is straightforward: update to 1.4.7 or later, or uninstall the client if it is no longer needed. That second option deserves more attention than it usually gets, because remote access clients accumulate. A laptop that has supported six vendors over four years carries six clients, five of which are for equipment nobody services any more, all of them running services and none of them being patched.

IXON's cloud has rejected connections from unpatched clients since 5 August, which is a defensible piece of vendor behaviour — it converts a vulnerability that depends on customer action into one that mostly enforces itself. It also means a client that suddenly stopped connecting last month was telling you something.

Affected sectors are Commercial Facilities, Critical Manufacturing, Energy, Information Technology, and Water and Wastewater, deployed worldwide from the Netherlands-headquartered vendor. The flaw was found and reported internally at IXON.

Source: CISA

Want to work with us?

Tell us what you're building and we'll help you scope the first deployment.