PT-2025-20286 · Unknown+1 · Dropbear Ssh+1

Marcin Nowak

·

Published

2025-05-07

·

Updated

2025-09-03

·

CVE-2025-47203

CVSS v3.1

4.5

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Dropbear SSH versions prior to 2025.88
Description The issue allows command injection via an untrusted hostname argument, because a shell is used. This occurs when the dbclient in Dropbear SSH is used with an untrusted hostname.
Recommendations For versions prior to 2025.88, update to version 2025.88 or later to resolve the issue. As a temporary workaround, consider validating and sanitizing all hostname arguments to prevent command injection. Restrict access to the dbclient until the issue is resolved.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-47203
DLA-4169-1
MGASA-2025-0158

Affected Products

Debian
Dropbear Ssh