CVE-2025-15387: Qno Technology VPN Firewall

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

VPN Firewall developed by QNO Technology has a Insufficient Entropy vulnerability, allowing unauthenticated remote attackers to obtain any logged-in user session through brute-force attacks and subsequently log into the system.

Affected products

Published 2025-12-31. Last modified 2026-06-17.