CVE-2020-29238: Expressvpn

High severity, CVSS 7.5. EPSS: 16.5% chance of exploitation in the next 30 days.

An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensitive information when the server running as reverse proxy via specially crafted request.

Affected products

Published 2021-03-10. Last modified 2026-07-09.