Top VPN services can be tricked into leaking traffic outside your network

A button with the caption VPN
(Image credit: Shutterstock)

Two vulnerabilities found in popular business VPN solutions could allow hackers to divert traffic outside a VPN tunnel, among other things. 

A new research paper, recently published by a group of authors from different universities around the world, outlined two vulnerabilities affecting Cisco routers were mentioned - CVE-2023-36672, and CVE-2023-36673. 

The flaws, collectively titled TunnelCrack, affect Cisco Secure Client AnyConnect VPN for iOS regardless of client configuration.

Manipulating routing exceptions

The paper, titled Bypassing tunnels: “Leaking VPN client traffic by abusing routing tables” was written by Nian Xue of the New York University, together with Yashaswi Malla, Zihang Xia, and Christina Popper of the New York University Abu Dhabi, and Mathy Vanhoef from the imec-DistriNet, KU Leuven.

“Our first set of vulnerabilities, called LocalNet attacks, can be exploited when a user connects to an untrusted Wi-Fi network,” one of the researchers - Mathy Vanhoef - told The Register. “Our second set of vulnerabilities, called ServerIP attacks, can be exploited by untrusted Wi-Fi networks and by malicious Internet service providers. Both attacks manipulate the victim's routing table to trick the victim into sending traffic outside the protected VPN tunnel, allowing an adversary to read and intercept transmitted traffic.”

Soon after the paper was published, Cisco sounded the alarm, saying the vulnerabilities can be abused by an attacker to “manipulate routing exceptions that are maintained by the client to redirect traffic to a device that they control without the benefit of the VPN tunnel encryption." However, no patch seems to be required, as Cisco only said that a few properly configured firewall rules should do the trick.

"For customers who have configured clients to allow local LAN access, Cisco recommends applying client firewall rules to allow access to necessary resources only," the networking giant said.

Via: The Register

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A VPN runs on a mobile phone placed on a laptop keyboard
Major new online tunneling vulnerability could put millions of devices at risk
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
vpn
Ivanti warns another critical security flaw is being attacked
China
Juniper patches security flaws which could have let hackers take over your router
An image of network security icons for a network encircling a digital blue earth.
Industrial networks exposed to attack by faulty Moxa devices
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Latest in VPN Privacy & Security
Swiss flag with view of Geneva city, Switzerland
Secure encryption and online anonymity are now at risk in Switzerland – here's what you need to know
Demonstrators protesting against the arrest of the Mayor of Istanbul Ekrem Imamoglu block Atatürk Boulevard on March 22, 2025 in Ankara, Türkiye.
Turkey's social media ban has been lifted, but VPN usage is still high
Shape of Russia filled with Russian flag-colored internet codes on a black hacking background
A new wave of blocks in Russia targets VPN apps and Cloudflare subnets
Digital hand set location on map with two pins. AI technology in GPs, innovation delivery, map location, future transport logistic, route path concept. GPs point. New office location, change address
What does your IP address reveal about you?
A stethoscope next to a laptop on a pink background
How to check if your VPN is working
Teenager playing on a gaming PC with two monitors
Is using a VPN while gaming cheating? 5 myths you shouldn't believe about gaming with a VPN
Latest in News
Buzz Lightyear Space Ranger Spin Rennovations
Disney’s giving a classic Buzz Lightyear ride a tech overhaul – here's everything you need to know
Hisense U8 series TV on wall in living room
Hisense announces 2025 mini-LED TV lineup, with screen sizes up to 100 inches – and a surprising smart TV switch
Nintendo Music teaser art
Nintendo Music expands its library with songs from Kirby and the Forgotten Land and Tetris
Opera AI Tabs
Opera's new AI feature brings order to your browser tab chaos
An image of Pro-Ject's Flatten it closed and opened
Pro-Ject’s new vinyl flattener will fix any warped LPs you inadvertently buy on Record Store Day
The iPhone 16 Pro on a grey background
iPhone 17 Pro tipped to get 8K video recording – but I want these 3 video features instead