CVE-2026-75925
IXON VPN Client CRLF Injection Vulnerability
Halo Surface Signal: 2 out of 5 — less likely to be public-facing.
Improper handling of CRLF sequences in the IXON VPN Client allows an unauthenticated attacker to execute commands with root or SYSTEM privileges. This vulnerability persists across restarts and is not visually apparent to users, posing a risk to affected systems.