
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2018-25368 is a denial-of-service (DoS) vulnerability in NordVPN version 6.14.31 that allows unauthenticated attackers to crash the application by submitting an excessively long string in the password field. The vulnerability was originally discovered in 2018 but was formally assigned a CVE and published on May 25, 2026, with the CVE status listed as "Deferred." It affects NordVPN versions up to and including 6.14.31. The CVSS v3.1 base score is 7.5 (High), while the CVSS v4.0 base score is 8.7 (High) (VulnCheck Advisory, EUVD).
The root cause is classified as CWE-789 (Memory Allocation with Excessive Size Value), where the application fails to enforce input length limits on the password field during authentication. An attacker can paste a buffer of repeated characters into the password input field, causing the application to attempt an excessively large memory allocation, which triggers a crash. No authentication or special privileges are required to trigger the vulnerability — only network access to the login interface is needed. A public proof-of-concept exploit has been available on Exploit-DB since 2018 (Exploit-DB, VulnCheck Advisory).
Successful exploitation causes the NordVPN client application to crash, disrupting VPN connectivity for the affected user. While the primary impact is availability loss (loss of VPN protection), the CVSS scoring also reflects a high confidentiality impact, potentially because a crashed VPN client may expose the user's real IP address and unencrypted traffic. Integrity is not directly affected, and there is no indication of lateral movement potential or remote code execution capability (VulnCheck Advisory).
A public proof-of-concept exploit has been available on Exploit-DB (EDB-ID 45304) since 2018, making this vulnerability trivially reproducible. The EPSS score is approximately 0.048%, indicating a low probability of active exploitation in the wild at this time. There is no known threat actor attribution, no evidence of active in-the-wild exploitation campaigns, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Exploit-DB, VulnCheck Advisory).
nordvpn.exe on Windows) without user-initiated action.Users should upgrade NordVPN to a version newer than 6.14.31, as the affected version is significantly outdated. NordVPN provides updated client software via their official download page. No specific configuration-based workaround is documented; the primary remediation is to update to a current, patched version of the client (NordVPN Download).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."