CVE-2018-25368: Nordvpn
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting an excessively long string in the password field. Attackers can paste a buffer of repeated characters into the password input field to trigger an application crash when attempting to authenticate.
Affected products
- Nordvpn Nordvpn: up to and including 6.14.31
Published 2026-05-25. Last modified 2026-10-06.