#VU121011 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in coTURN - CVE-2025-69217
Published: January 7, 2026
coTURN
coTURN
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to usage of bad random number generator for nonces and port randomization after refactoring. A remote attacker can send 50 unauthenticated allocations requests and completely reconstruct the current state of the random number generator, leading to spoofing. authentication bypass and denial of service.