CVE-2014-9754: Viprinet Multichannel VPN Router 300 Firmware

Medium severity, CVSS 5.9. EPSS: 1.7% chance of exploitation in the next 30 days.

The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (through the checking of the endpoint's SSL key) before initiating the exchange, which allows an attacker to perform a Man in the Middle attack.

Affected products

  • Viprinet Multichannel VPN Router 300 Firmware: version 2013070830 only; version 2013080900 only

Published 2017-01-20. Last modified 2026-06-17.