logo

Watch out for rogue DHCP servers decloaking your VPN connections

ID: f2debabb-9a43-5bad-be3c-ce39c3c9e8a0

STIX ID: report--f2debabb-9a43-5bad-be3c-ce39c3c9e8a0

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-05-07

Date Updated: 2026-04-26

Author: Brandon Vigliarolo

...
...

Researchers disclosed 'TunnelVision' (CVE-2024-3661), a DHCP option 121 abuse that allows an attacker controlling a DHCP server on the same LAN to inject routes that divert VPN traffic outside encrypted tunnels; most VPNs and kill-switches do not detect the reroute, Android is not affected, and mitigations (network namespaces, DHCP filtering, dedicated hotspots) are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.