CVE-2025-47203

dbclient in Dropbear SSH before 2025.88 allows command injection via an untrusted hostname argument, because a shell is used.
Configurations

No configuration.

History

13 May 2025, 21:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/05/13/10 -

13 May 2025, 18:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/05/13/3 -

13 May 2025, 03:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/05/13/1 -

12 May 2025, 22:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/05/12/6 -

09 May 2025, 19:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/05/09/4 -

08 May 2025, 14:39

Type Values Removed Values Added
Summary
  • (es) dbclient en Dropbear SSH anterior a 2025.88 permite la inyección de comandos a través de un argumento de nombre de host no confiable, porque se utiliza un shell.

07 May 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-07 18:15

Updated : 2025-05-13 21:16


NVD link : CVE-2025-47203

Mitre link : CVE-2025-47203

CVE.ORG link : CVE-2025-47203


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')