CVE-2020-29238: Expressvpn
High severity, CVSS 7.5. EPSS: 16.5% chance of exploitation in the next 30 days.
An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensitive information when the server running as reverse proxy via specially crafted request.
Affected products
- Expressvpn Expressvpn: version 1.0 only
Published 2021-03-10. Last modified 2026-07-09.