A vulnerability marked as critical has been reported in OpenVPN up to 2.7_beta1 on POSIX. This impacts an unknown function. This manipulation causes os command injection.

This vulnerability is tracked as CVE-2025-10680. The attack is possible to be carried out remotely. No exploit exists.