Security Research

CVE-2025-0282 Ivanti Connect Secure Pre-Auth Stack Overflow RCE: Buffer Overflow on the VPN Gateway

#Vulnerability Analysis#Code Audit#Cyber Attack
CVE-2025-0282 Ivanti Connect Secure Pre-Auth Stack Overflow RCE: Buffer Overflow on the VPN Gateway

Ivanti Connect Secure exposes the pre-authentication welcome.cgi endpoint directly to the internet without any length check on request parameters — an attacker fills the stack buffer with 500 A’s, overwrites the return address with system(), and gets arbitrary command execution on the VPN gateway without any credentials.

Unlock to view this content.