---
id: CVE-2025-66575
title: >-
  VeeVPN 1.6.1 contains an unquoted service path vulnerability in the
  VeePNService that allows remote attackers to execute code during startup or
  reboot with escalated privileges
summary: >-
  VeeVPN 1.6.1 contains an unquoted service path vulnerability in the
  VeePNService that allows remote attackers to execute code during startup or
  reboot with escalated privileges. Attackers can exploit this by providing a
  malicious service…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-428
vendor: veepn
product: veepn
affected:
  - veepn = 1.6.1
published: '2025-12-04'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-66575'
references:
  - url: 'https://github.com/veepn/veepn'
    label: disclosure@vulncheck.com
  - url: 'https://veepn.com/'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/52088'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/veevpn-161-unquoted-service-path-remote-code-execution
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/52088'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00459
epssPercentile: 0.37152
ingestedAt: '2026-09-25T23:21:16.879Z'
---

## Overview

VeeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute code during startup or reboot with escalated privileges. Attackers can exploit this by providing a malicious service name, allowing them to inject commands and run as LocalSystem.

## Affected

- `veepn = 1.6.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
