WireGuard Easy Vulnerability Allows Unauthorized Credential Recovery
A critical flaw in WireGuard Easy allows unauthenticated attackers to brute-force weak tokens and hijack VPN peer credentials.
WireGuard Easy versions up to 15.3.0 contain a critical vulnerability, tracked as CVE-2026-63089, involving cryptographically weak one-time link token generation. The issue stems from the use of CRC32 to compute tokens based on a limited range of random values, creating a small keyspace of only 1,000 possibilities per client ID.
Because the /cnf/:oneTimeLink route lacks rate limiting and does not properly validate token expiration, unauthenticated network attackers can brute-force these tokens to recover a peer's PrivateKey and PresharedKey. Successful exploitation allows an attacker to impersonate the compromised peer on the VPN network.
Users are advised to update to the version containing the fix identified in commit 66b292b to mitigate this risk.
Sources
- GitHub Security Advisories Original source
Continue Reading
FulcrumSec Claims Manchester Airport Breach, 86 GB Stolen
Extortion group FulcrumSec says it stole 86 GB from Manchester Airports Group, exposing detailed travel data.
Anthropic tackles Claude session hijacking via infostealers
Anthropic warns that infostealer malware is stealing Claude login sessions to drain accounts.
AI agents can be tricked into installing malware via unclaimed code packages
Researchers found 120 unregistered domains in AI documentation that could be hijacked to infect corporate networks.