CVE-2026-2542 | Total VPN 0.5.29.0 on Windows win-service.exe unquoted search path (EUVD-2026-6120)
A vulnerability was found in Total VPN 0.5.29.0 on Windows and classified as problematic. Affected by this vulnerability is an unknown functionality of the file C:\Program Files\Total VPN\win-service.exe. Executing a manipulation can lead to unquoted search path.
This vulnerability is handled as CVE-2026-2542. It is possible to launch the attack on the local host. There is not any exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.