CVE-2026-75925 describes a critical CRLF injection vulnerability in IXON VPN Client versions prior to 1.4.7. The flaw allows an attacker to inject arbitrary configuration directives into a file consumed by a privileged subprocess, enabling command execution as root or SYSTEM. The local configuration service accepts changes without any authentication or origin verification, making exploitation straightforward. Injected configurations persist across reboots and VPN restarts, providing long-term persistence with no visible behavioral change to the user. The vulnerability is classified under CWE as improper neutralization of CRLF sequences. CISA has issued an ICS advisory (ICSA-26-246-02) regarding this vulnerability. IXON has also published their own security advisory. Users are urged to upgrade to version 1.4.7 or later to remediate the issue.