CVE-2018-25368
NordVPN vulnerability analysis and mitigation

Overview

CVE-2018-25368 is a denial-of-service (DoS) vulnerability in NordVPN version 6.14.31 that allows unauthenticated attackers to crash the application by submitting an excessively long string in the password field. The vulnerability was originally discovered in 2018 but was formally assigned a CVE and published on May 25, 2026, with the CVE status listed as "Deferred." It affects NordVPN versions up to and including 6.14.31. The CVSS v3.1 base score is 7.5 (High), while the CVSS v4.0 base score is 8.7 (High) (VulnCheck Advisory, EUVD).

Technical details

The root cause is classified as CWE-789 (Memory Allocation with Excessive Size Value), where the application fails to enforce input length limits on the password field during authentication. An attacker can paste a buffer of repeated characters into the password input field, causing the application to attempt an excessively large memory allocation, which triggers a crash. No authentication or special privileges are required to trigger the vulnerability — only network access to the login interface is needed. A public proof-of-concept exploit has been available on Exploit-DB since 2018 (Exploit-DB, VulnCheck Advisory).

Impact

Successful exploitation causes the NordVPN client application to crash, disrupting VPN connectivity for the affected user. While the primary impact is availability loss (loss of VPN protection), the CVSS scoring also reflects a high confidentiality impact, potentially because a crashed VPN client may expose the user's real IP address and unencrypted traffic. Integrity is not directly affected, and there is no indication of lateral movement potential or remote code execution capability (VulnCheck Advisory).

Exploitability

A public proof-of-concept exploit has been available on Exploit-DB (EDB-ID 45304) since 2018, making this vulnerability trivially reproducible. The EPSS score is approximately 0.048%, indicating a low probability of active exploitation in the wild at this time. There is no known threat actor attribution, no evidence of active in-the-wild exploitation campaigns, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Exploit-DB, VulnCheck Advisory).

Exploitation steps

  1. Identify target: Confirm the target is running NordVPN version 6.14.31 or earlier on a supported platform.
  2. Access the login interface: Open the NordVPN client application to reach the authentication (login) screen.
  3. Craft the payload: Generate a very long string of repeated characters (e.g., thousands of the same character) to serve as the password input.
  4. Submit the payload: Paste the excessively long string into the password field and attempt to authenticate.
  5. Trigger crash: The application attempts to process the oversized input, triggering an excessive memory allocation (CWE-789) that causes the NordVPN client to crash, dropping the user's VPN connection (Exploit-DB).

Indicators of compromise

  • Application Behavior: NordVPN client crashes unexpectedly during or immediately after a login attempt.
  • Logs: Application error logs showing memory allocation failures or unhandled exceptions in the NordVPN process around authentication events.
  • Process: Unexpected termination of the NordVPN process (e.g., nordvpn.exe on Windows) without user-initiated action.
  • Network: Sudden loss of VPN tunnel (traffic reverting to direct/unencrypted connection) coinciding with a login attempt.

Mitigation and workarounds

Users should upgrade NordVPN to a version newer than 6.14.31, as the affected version is significantly outdated. NordVPN provides updated client software via their official download page. No specific configuration-based workaround is documented; the primary remediation is to update to a current, patched version of the client (NordVPN Download).

Additional resources


SourceThis report was generated using AI

Related NordVPN vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2018-10170CRITICAL9.8
  • NixOS logoNixOS
  • nordvpn
NoYesApr 16, 2018
CVE-2018-3952HIGH8.8
  • NixOS logoNixOS
  • nordvpn
NoNoSep 07, 2018
CVE-2018-25368HIGH8.7
  • NordVPN logoNordVPN
  • cpe:2.3:a:nordvpn:nordvpn
NoNoMay 25, 2026
CVE-2020-36992HIGH8.5
  • NordVPN logoNordVPN
  • cpe:2.3:a:nordvpn:nordvpn
NoNoJan 28, 2026
CVE-2019-25572MEDIUM6.9
  • NixOS logoNixOS
  • nordvpn
NoYesMar 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management