Executive brief
WireGuard Easy, a management interface for WireGuard VPNs, contains a security flaw in how it generates one-time setup links for new users. Because these links are generated using a very small pool of predictable numbers, an attacker can easily guess the link and steal a user's private VPN credentials. This allows an unauthorized person to impersonate legitimate users and gain full access to the private corporate or home network protected by the VPN.
Technical details
A vulnerability in WireGuard Easy (up to version 15.3.0) stems from the use of a cryptographically weak PRNG for one-time link (OTL) tokens. The tokens are generated by computing a CRC32 hash over a random integer constrained to a range of only 0-999, resulting in a keyspace of just 1,000 possible values. An unauthenticated remote attacker can brute-force these tokens via the '/cnf/:oneTimeLink' route, which lacks rate limiting and fails to validate token expiration. Successful exploitation allows the retrieval of a peer's PrivateKey and PresharedKey. The issue is addressed in commit 66b292b.
Affected products
- wg-easy wg-easy through 15.3.0
Timeline
- 2026-06-12: patched: Fix merged in PR #2661
- 2026-07-16: advisory: NVD and VulnCheck advisory published