Accel-ppp-ng never verifies the Response Authenticator (RA) field on RADIUS Access-Accept packets. RFC 2865 §3 requires that NAS clients validate this field using the shared secret before acting on the response. Because the check is absent, any host that can deliver a UDP packet to the accel-ppp process's configured RADIUS source socket can forge an Access-Accept and authenticate arbitrary VPN clients — without knowing the shared secret and without interacting with the legitimate RADIUS server.
Description
Description
Details
Details
- Version
- -
- Is it a breaking change?
- Unspecified (possibly destroys the router)
- Issue type
- Unspecified (please specify)