NextVPN 4.10 contains an insecure file permissions vulnerability that allows local users to modify executable files with full access rights. Attackers can replace system executables with malicious files to gain SYSTEM or Administrator privileges through unauthorized file modification.
Metrics
Affected Vendors & Products
References
History
Fri, 13 Feb 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vm3max
Vm3max nextvpn |
|
| Vendors & Products |
Vm3max
Vm3max nextvpn |
Thu, 12 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Feb 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NextVPN 4.10 contains an insecure file permissions vulnerability that allows local users to modify executable files with full access rights. Attackers can replace system executables with malicious files to gain SYSTEM or Administrator privileges through unauthorized file modification. | |
| Title | NextVPN 4.10 - Insecure File Permissions | |
| Weaknesses | CWE-732 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-12T19:02:33.359Z
Updated: 2026-02-12T19:55:30.153Z
Reserved: 2026-02-12T18:28:05.299Z
Link: CVE-2019-25343
Updated: 2026-02-12T19:54:59.019Z
Status : Awaiting Analysis
Published: 2026-02-12T20:16:00.010
Modified: 2026-02-13T14:23:48.007
Link: CVE-2019-25343
No data.