CVE-2025-27093
vulnerability analysis and mitigation

Overview

CVE-2025-27093 affects Sliver, a command and control framework that uses a custom Wireguard netstack. The vulnerability was discovered in versions 1.5.43 and earlier, and in development version 1.6.0-dev, where the netstack implementation fails to limit traffic between Wireguard clients. This security flaw was disclosed on October 28, 2025, and received a CVSS v3.1 base score of 6.3 (Medium) (GitHub Advisory).

Technical details

The vulnerability stems from the netstack's failure to implement traffic filtering between connected Wireguard clients. The implementation treats operators' Wireguard config and beacon/session's Wireguard config equally, allowing them both to connect to the wireguard listener created from the CLI. When services listen on 0.0.0.0, they become accessible on the wireguard interface's IP address (e.g., 100.64.0.3), exposing services like SSH, RDP, and SMB. The CVSS vector string is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L, indicating network attack vector with low complexity (GitHub Advisory).

Impact

The vulnerability primarily affects operator machines. If their services contain vulnerabilities, attackers can potentially achieve Remote Code Execution (RCE). Even without exploiting service vulnerabilities, attackers can gather sensitive information such as hostnames and SSH signatures. Additionally, compromised beacon keypairs can be used to attack operators, and port forwardings become accessible from other implants (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched with the implementation of traffic filtering between clients using a default-deny policy. The fix includes differentiating between operators and beacons' wireguard config/client and only allowing specific one-way traffic when the operator requests to open a Wireguard port forward. Users should upgrade to version 1.5.44 or later (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management