CVE-2025-15389: Qno Technology VPN Firewall

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

VPN Firewall developed by QNO Technology has an OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server.

Affected products

Published 2025-12-31. Last modified 2026-06-17.