CVE-2016-5673: Ultravnc Repeater

High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.

UltraVNC Repeater before 1300 does not restrict destination IP addresses or TCP ports, which allows remote attackers to obtain open-proxy functionality by using a :: substring in between the IP address and port number.

Affected products

  • Ultravnc Repeater: up to and including 1201

Published 2016-08-25. Last modified 2026-06-17.