CVE-2024-3661
DHCP routing options can manipulate interface-based VPN traffic
- Published
- May 6, 2024
- Updated
- Aug 28, 2024
- Assigning CNA
- cisa-cg
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:LLow · next 30 days
- Percentile
- 90.2%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.
Sources
3Exploit tool targeting CVE-2024-3661 in VPN products, providing proof-of-concept code for security testing and vulnerability verification.
Demo TunnelVision vulnerability for VPN using DHCP option 121
CVE-2024-3661 TunnelVision
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.