Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 14 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Softether
Softether softethervpn |
|
| CPEs | cpe:2.3:a:softether:softethervpn:*:*:*:*:developer:*:*:* | |
| Vendors & Products |
Softether
Softether softethervpn |
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Softethervpn
Softethervpn softethervpn |
|
| Vendors & Products |
Softethervpn
Softethervpn softethervpn |
Tue, 07 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. In 5.2.5188 and earlier, a pre-authentication denial-of-service vulnerability exists in SoftEther VPN Developer Edition 5.2.5188 (and likely earlier versions of Developer Edition). An unauthenticated remote attacker can crash the vpnserver process by sending a single malformed EAP-TLS packet over raw L2TP (UDP/1701), terminating all active VPN sessions. | |
| Title | Pre-Auth EAP-TLS DoS on SoftEther VPN Developer Edition | |
| Weaknesses | CWE-789 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-07T17:27:16.498Z
Reserved: 2026-04-06T19:31:07.265Z
Link: CVE-2026-39312
Updated: 2026-04-07T17:27:08.391Z
Status : Analyzed
Published: 2026-04-07T17:16:36.920
Modified: 2026-04-14T20:08:38.900
Link: CVE-2026-39312
No data.
OpenCVE Enrichment
Updated: 2026-04-15T16:30:09Z