CVE-2025-27093 - CVE House
Back to Database
Status published Medium CVE-2025-27093

Sliver does not restricted traffic between Wireguard clients.

Vulnerability Description

Sliver is a command and control framework that uses a custom Wireguard netstack. In versions 1.5.43 and earlier, and in development version 1.6.0-dev, the netstack does not limit traffic between Wireguard clients. This allows clients to communicate with each other unrestrictedly, potentially enabling leaked or recovered keypairs to be used to attack operators or allowing port forwardings to be accessible from other implants.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-27093

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

sliver
Vulnerable Versions:
<= 1.5.43

Timeline

Official Publish: October 28th, 2025
Last Modified: October 29th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

Weaknesses (CWE)