PT-2025-17962 · Unknown+1 · Formidable+1

Tunnckocore

·

Published

2025-04-26

·

Updated

2025-12-24

·

CVE-2025-46653

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Formidable versions 2.1.0 through 3.x before 3.5.3
Description The issue relies on hexoid to prevent guessing of filenames for untrusted executable content. However, hexoid is documented as not cryptographically secure. There is a scenario in which only the last two characters of a hexoid string need to be guessed.
Recommendations For versions 2.1.0 through 3.x before 3.5.3, update to version 3.5.3 or later to resolve the issue.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-46653
GHSA-75V8-2H7P-7M2M

Affected Products

Debian
Formidable