DesignRush
  • AGENCY DIRECTORY
    Branding & Creative
    Website & Interface
    Marketing
    Software & App
    IT Services
    Branding & Creative
    • Full-service Digital
    • Creative Agencies
    • Product Design
    • Logo Design Companies
    • Graphic Design Companies
    • Package Design
    • Video Production Companies
    • PR Agencies
    • Design Studios
    • Reputation Management
    Branding & Creative
    Website & Interface
    • Web Design Companies
    • eCommerce Development
    • Web Development Companies
    • WordPress Web Design Companies
    • WordPress Development Companies
    • Magento Development Companies
    • Shopify eCommerce Development
    • UX Designers
    • Small Business Web Design
    Website & Interface
    Marketing
    • SEO Agencies
    • PPC Agencies
    • Social Media Marketing
    • Search Engine Marketing Agencies
    • Email Marketing
    • Small Business SEO Companies
    • Local SEO
    • Google Ads Agencies
    • Advertising Agencies
    • eCommerce SEO Agencies
    • Media Buying Agencies
    • Content Marketing Agencies
    • Lead Generation Companies
    Marketing
    Software & App
    • Software Development
    • Offshore Software Development
    • Outsourcing Software Development
    • Mobile App Developers
    • VR & Augmented Reality Companies
    • AI Companies
    • Android App Development Companies
    • iOS Development Companies
    • Blockchain Development Companies
    • Software Testing
    Software & App
    IT Services
    • IT Services Companies
    • IT Outsourcing Companies
    • Managed Service Providers
    • Cybersecurity Companies
    • Big Data Analytics Companies
    • Cloud Consulting Companies
    • Staff Augmentation Services
    • SharePoint Consultants
    IT Services
  • List Your AgencyFind An Agency
  • Marketplace
  • Awards
    DesignRush Design Awards
    Award Winners by Category:
    • All the Latest Winners
    • Website Design Awards
    • App Design Awards
    • Logo Design Awards
    • Print Design Awards
    • Packaging Design Awards
    • Video Design Awards

    Each month we evaluate and recognize award-winning designs in these industries.

    see the latest winners
    Looking for Inspiration?

    Browse the best designs by category:

    • Best Website Designs
    • Best Logo Designs
    • Best Print Designs
    • Best App Designs
    • Best Packaging Designs
    • Best Video Designs
  • Trending Brands
List Your AgencyFind An Agency
Trending Brands
  • Latest News
  • Interviews
  • Podcast
  • Trends
  • Trending Brands
  • Shelltrail Uncovers IXON VPN Flaws Exposing Windows & Linux Systems to Hackers
Join Our Newsletter
Get your weekly dose of news, interviews & trends
Join our newsletter
Join Our Newsletter
Get your weekly dose of news, interviews & trends
Thanks for subscribing!
Join our newsletter
By completing this form you agree to the Terms of Use & IP and our Privacy Policy
Want to be Featured?
Contact our news team at spotlight@designrush.com
Get in touch

Shelltrail Uncovers IXON VPN Flaws Exposing Windows & Linux Systems to Hackers

Cybersecurity
Shelltrail Uncovers IXON VPN Flaws Exposing Windows & Linux Systems to Hackers
[Source: Shelltrail]
Article by Roberto OrosaRoberto Orosa
3 min read
Published: April 29, 2025

Key Takeaways:

  • Shelltrail discovered three critical vulnerabilities in the IXON VPN client, exposing industrial systems to privilege escalation attacks on Windows and Linux.
  • Two of the flaws have been patched in version 1.4.4, preventing attackers from injecting malicious OpenVPN configurations that could lead to full system access.
  • A third vulnerability remains undisclosed while IXON develops a fix, highlighting the need for continuous vulnerability assessments in cloud-connected industrial software.

Three major flaws in IXON’s VPN software could let hackers take control of industrial systems with just a few lines of code.

Cybersecurity firm Shelltrail recently disclosed vulnerabilities in the IXON VPN client that allow local privilege escalation (LPE) on both Windows and Linux platforms.

Two of the bugs, now identified as "CVE-2025-ZZZ-02" and "CVE-2025-ZZZ-03," stem from how the VPN client handles temporary configuration files.

On Linux, the client saves OpenVPN configs to a predictable file in /tmp, which attackers can exploit by injecting malicious code using a simple named pipe.

Local VPN Client Configuration Details
Local VPN Client Configuration Details | Source: Shelltrail

On Windows, a race condition in the C:\Windows\Temp folder enables attackers to overwrite temp files and execute arbitrary code with SYSTEM-level access — no VPN connection even required.

Shelltrail is withholding technical details of a third, still-unpatched vulnerability (CVE-2025-ZZZ-01) to prevent misuse.

MITRE has yet to assign official CVE numbers due to a backlog.

Even well-designed interfaces can mask deeper architectural flaws, particularly in how systems handle file permissions and temporary storage.

It shows the critical need for cybersecurity firms to conduct deep system-level audits.

Ammar Naeem, marketing strategist at AstrillVPN, warns that even minor bugs in remote access tools can pose major security risks for organizations.

"Small software bugs in remote access tools can have outsized consequences because these tools act as gateways to critical systems and data. Even seemingly minor flaws can be exploited by attackers to gain unauthorized access, bypass security controls, or elevate privileges — essentially handing them the keys to the network.

Since many organizations rely on the same popular remote access software, a single vulnerability can put thousands of businesses at risk simultaneously. These bugs can lead to data breaches, service disruptions, and even large-scale attacks like ransomware or cryptojacking."

This is especially true within automation-heavy industries where local services and user privilege boundaries are often overlooked.

What Went Wrong?

IXON is a Dutch provider of remote access solutions for industrial systems.

Its VPN client connects devices through a cloud portal and runs a local web server (https://localhost:9250) with elevated system privileges.

The vulnerabilities occur when the client fetches OpenVPN config files after a user initiates a connection.

This data exchange is done via an XHR request from the browser to the local server, which forwards it to the IXON cloud that receives the final configuration.

VPN settings showing TCP and proxy options on the IXON Cloud platform | Source: Cybersecurity News
VPN Settings Showing TCP and Proxy Options on the IXON Cloud Platform | Source: Shelltrail

Because these files are written to disk with loose permissions, attackers with access to the same machine can hijack the process and escalate privileges.

In response, IXON’s latest patch now stores the configuration files in restricted directories, limiting access to high-privilege users only.

Customers have been urged to update to version 1.4.4 and monitor further disclosures from IXON’s advisory page.

For industrial operations relying on always-on remote access, securing local services is just as critical as encrypting traffic.

As Aviv Besinsky, director of solutions architecture at Bright Data points out, you don’t have to sit idly while waiting for that patch. Implementing simple steps today can keep your operations running smoothly.

“After updating to the 1.4.4 patch, keep any potential fallout small by carving your VPN into its own little bubble. Ensure only the critical machines get access. Turn on real‑time alerts so you spot funny business before it spirals into a breach. Bring in a trusted security partner to handle audits and compliance checks.

Your team can focus on core projects instead of paperwork. And don’t leave your C‑suite in the dark. A quick, regular update keeps everyone calm and ready, instead of scrambling if something pops up.”

IXON's case shows how small oversights in local file handling can undermine the security of entire networks.

Recently, Bybit and other major financial firms were victims of targeted cyberattacks, losing millions in the process.

Tags:
ixon vpn linux shelltrail windows 
Roberto Orosa
Roberto Orosa
B2B Reporter
Roberto Orosa has worked in a variety of industries, with four years of experience in copywriting and publishing. His fascination with tech, business, and all the latest trends led him to cover breaking B2B news for DesignRush.
Follow on: LinkedIn Send email: roberto.o@designrush.com
Want to be Featured?
Contact our news team at spotlight@designrush.com
Get in touch

Latest Cybersecurity News

view all
Why Your Digital Agency Shouldn’t Rely on Free or Generic VPNs
By Andrea Surnit  |  3 weeks ago  |  3 min read
A smiling man with an arrest warrant (WARNART) in McAfee's new ad holding two thumbs up
McAfee Exposes the New Face of Scams in AI-Led Campaign from VSA Partners
By Roberto Orosa  |  3 weeks ago  |  3 min read
Illustration of a man standing in front of a shield in a cyber world
7 Reasons Why Your VPN Provider Could Make or Break Your Business Security
By Ilze-Mari Grundling  |  1 month ago  |  3 min read
Vector image from BlueGrid
43% of Data Breaches Hit SMBs – Here’s How to Avoid Becoming a Target
By Roberto Orosa  |  2 months ago  |  3 min read
view all

Most Popular Cybersecurity Stories

A smiling man with an arrest warrant (WARNART) in McAfee's new ad holding two thumbs up
McAfee Exposes the New Face of Scams in AI-Led Campaign from VSA Partners
By Roberto Orosa  |  3 weeks ago  |  3 min read
Why Your Digital Agency Shouldn’t Rely on Free or Generic VPNs
By Andrea Surnit  |  3 weeks ago  |  3 min read
Illustration of a man standing in front of a shield in a cyber world
7 Reasons Why Your VPN Provider Could Make or Break Your Business Security
By Ilze-Mari Grundling  |  1 month ago  |  3 min read
A teen showing off his muscles with the mirror showing his mom taking the photo
Apple's New 'Clean Up' Commercial Hits Home with Relatable Humor
By Roberto Orosa  |  1 month ago  |  2 min read
DesignRush

DesignRush is the premier agency directory, awards platform, and media hub connecting brands with top agencies in software, app development, design, and marketing. We deliver vetted reviews, insights, and trends to drive business growth.

For Businesses

  • Agencies Categories
  • Agency Ranking Methodology
  • Trends Articles
  • FAQs

For Agencies

  • Benefits Of Listing With Us
  • Submit An Agency
  • Sponsorship
  • All Agencies

About DesignRush

  • Team & Story
  • Press Releases

Get in Touch

18117 Biscayne Blvd
Miami, FL 33160
United States
  • Contact Us
© DesignRush 2025, All Rights Reserved
  • Sitemap
  • Terms of Use & IP
  • Privacy Policy
  • Accessibility
  • Fraud Protection