PT-2025-18214 · Finit+1 · Finit+1
Troglobit
·
Published
2025-03-18
·
Updated
2025-06-23
·
CVE-2025-29906
CVSS v3.1
8.6
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Finit versions 3.0-rc1 through 4.11
Description
Finit is a fast init for Linux systems. The issue concerns the implementation of getty for the
tty configuration directive, which can bypass /bin/login, allowing a user to log in as any user without authentication. This can be exploited by manipulating the login prompt and requires access to the console. The problem has been patched in version 4.11.Recommendations
To resolve the issue, update to version 4.11 or later, as this version includes the patch for the authentication bypass issue.
As a temporary workaround, consider restricting access to the console to minimize the risk of exploitation.
Exploit
Fix
LPE
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Finit