QNO Technology VPN Firewall Insufficient Entropy Vulnerability Allowing Session Hijacking

Vulnerability

A vulnerability in QNO Technology's VPN Firewall has been identified, characterized by insufficient entropy. This flaw allows unauthenticated remote attackers to perform brute-force attacks to obtain any logged-in user session, subsequently gaining unauthorized access to the system.

Impact

Exploitation of this vulnerability allows for unauthorized access to user accounts by hijacking active sessions.

Added: Dec 31, 2025, 9:21 AM
Updated: Dec 31, 2025, 9:21 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.6
remediation
0.0
relevance
1.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.