Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-93337— NetworkManager-l2tp Privilege Escalation via pppd Plugin Injection

Quick assessment

Affected
nm-l2tp NetworkManager-l2tp
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

NetworkManager-l2tp 存在一个输入校验不当的漏洞,允许具有创建 VPN 连接权限的本地用户通过提供在有效整数后包含尾部非数字内容的 mru 或 mtu 属性值,注入任意的 pppd 指令。攻击者可以利用未经验证的字符串被逐字写入 pppd 选项文件(通过 write_config_option() 函数)这一机制,注入 plugin 指令,从而导致拥有 root 权限的 pppd 进程加载由攻击者控制的可共享对象,进而实现以 root 权限执行任意代码。

CVSS 7.8 · High

Affected Version Matrix 1

VendorProduct Version RangeStatus
nm-l2tp NetworkManager-l2tp ≤ 1.52.4 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93337

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
NetworkManager-l2tp Privilege Escalation via pppd Plugin Injection
Source: CVE Program / CVE List V5
Vulnerability Description
NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu property values containing trailing non-numeric content after a valid integer. Attackers can exploit the verbatim write of unvalidated strings into the pppd options file via write_config_option() to inject the plugin directive, causing the privileged pppd process to load an attacker-controlled shared object and achieve arbitrary code execution as root.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
参数注入或修改
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
nm-l2tp NetworkManager-l2tp 0 ~ 1.52.4 -

II. Public POCs for CVE-2026-93337

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93337

登录查看更多情报信息。

Patches & Fixes for CVE-2026-93337 (1)

Vendor Advisories for CVE-2026-93337 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-93337

No comments yet


Leave a comment