VYPR

wg-easy

by Wg Easy

CVEs (2)

  • CVE-2026-72603CriAug 11, 2026
    risk 0.65cvss 9.9epss 0.02

    An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard…

  • CVE-2026-63089CriJul 16, 2026
    risk 0.00cvss 9.3epss 0.00

    WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attackers to recover WireGuard peer credentials by brute-forcing a keyspace of at most 1000 candidate tokens…