PT-2025-25604 · Teleport · Teleport
Published
2025-06-16
·
Updated
2025-10-31
·
CVE-2025-49825
CVSS v2.0
10
10
Critical
| Base vector | Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Teleport versions prior to 17.5.2
Teleport versions 16.0.0 through 16.5.11
Teleport versions 15.0.0 through 15.5.2
Teleport versions 14.0.0 through 14.4.0
Teleport versions 13.0.0 through 13.4.26
Teleport versions 12.0.0 through 12.4.34
Teleport versions 0.0.11 through 12.4.34
Description
Teleport is susceptible to a remote authentication bypass, potentially allowing attackers to gain unauthorized access to systems. This issue affects Teleport agents and proxy servers. The vulnerability allows attackers to bypass SSH authentication entirely. The vulnerability has a CVSS score of 9.8 (Critical). While the vulnerability has not been actively exploited, all nodes should be updated to a patched version of Teleport. The vulnerability impacts systems running Teleport SSH agents, integrated OpenSSH deployments, and Teleport Git proxy server configurations.
Recommendations
Upgrade to Teleport version 17.5.2.
Upgrade to Teleport version 16.5.12.
Upgrade to Teleport version 15.5.3.
Upgrade to Teleport version 14.4.1.
Upgrade to Teleport version 13.4.27.
Upgrade to Teleport version 12.4.35.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
BDU:2025-14380
CVE-2025-49825
GHSA-8CQV-PJ7F-PWPC
GO-2025-3763
Affected Products
Teleport
References · 24
- https://bdu.fstec.ru/vul/2025-14380 · Security Note
- https://osv.dev/vulnerability/GHSA-8cqv-pj7f-pwpc · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-49825 · Security Note
- https://osv.dev/vulnerability/GO-2025-3763 · Vendor Advisory
- https://osv.dev/vulnerability/CVE-2025-49825 · Vendor Advisory
- https://github.com/gravitational/teleport/security/advisories/GHSA-8cqv-pj7f-pwpc⭐ 19412 🔗 1954 · Note
- https://github.com/gravitational/teleport⭐ 18646 🔗 1863 · Note
- https://reddit.com/r/cybersecurity/comments/1ldt42b/critical_teleport_auth_bypass_cve202549825_some · Reddit Post
- https://twitter.com/CVEnew/status/1935099022043435148 · Twitter Post
- https://goteleport.com/docs/changelog/#1753-063025 · Note
- https://goteleport.com/docs/ver/17.x/changelog/#1753-063025 · Note
- https://t.me/latest_high_impact_cve/2700 · Telegram Post
- https://t.me/cvenotify/126033 · Telegram Post
- https://twitter.com/pdnuclei_bot/status/1970986636721668343 · Twitter Post
- https://twitter.com/TweetThreatNews/status/1937161892398596286 · Twitter Post