Junglewise Threat Intelligence

CVE-2026-63089: wg-easy weak token generation in one-time link route

CVE-2026-63089 · Severity: critical · CVSS 9.3 · Published 2026-07-16

Executive brief

WireGuard Easy, a management interface for WireGuard VPNs, contains a security flaw in how it generates one-time setup links for new users. Because these links are generated using a very small pool of predictable numbers, an attacker can easily guess the link and steal a user's private VPN credentials. This allows an unauthorized person to impersonate legitimate users and gain full access to the private corporate or home network protected by the VPN.

Technical details

A vulnerability in WireGuard Easy (up to version 15.3.0) stems from the use of a cryptographically weak PRNG for one-time link (OTL) tokens. The tokens are generated by computing a CRC32 hash over a random integer constrained to a range of only 0-999, resulting in a keyspace of just 1,000 possible values. An unauthenticated remote attacker can brute-force these tokens via the '/cnf/:oneTimeLink' route, which lacks rate limiting and fails to validate token expiration. Successful exploitation allows the retrieval of a peer's PrivateKey and PresharedKey. The issue is addressed in commit 66b292b.

Affected products

  • wg-easy wg-easy through 15.3.0

Timeline

  • 2026-06-12: patched: Fix merged in PR #2661
  • 2026-07-16: advisory: NVD and VulnCheck advisory published

References

Related threats