PT-2025-39207 · Cryptolib · Cryptolib
Luiginoc
·
Published
2025-09-23
·
Updated
2026-02-10
·
CVE-2025-59534
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CryptoLib versions prior to 1.4.2
Description
CryptoLib is a software solution utilizing the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) for secure communications between spacecraft and ground stations. A command injection issue exists in the
initialize kerberos keytab file login() function due to the direct interpolation of user-controlled input into a shell command executed via the system() function without proper sanitization or validation. This allows for potential unauthorized command execution.Recommendations
Update CryptoLib to version 1.4.2 or later.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cryptolib