PT-2025-51833 · Dropbear+1 · Dropbear+1
Published
2025-01-01
·
Updated
2026-02-18
·
CVE-2025-14282
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Dropbear versions 2024.84 through 2025.88
Description
A flaw exists in Dropbear when operating in multi-user mode and authenticating users. The Dropbear SSH server performs socket forwardings as root, switching to the logged-in user only when a shell is spawned or file operations are performed. The introduction of unix domain socket forwarding allows any authenticated user to connect to any unix socket with root privileges, bypassing file system restrictions and
SO PEERCRED/SO PASSCRED checks. This could potentially allow an attacker to gain a root shell. The issue affects a significant number of routers and IoT devices. The vulnerability involves incorrect permission handling in the Dropbear SSH server.Recommendations
Upgrade Dropbear to version 2025.89 or later.
Fix
LPE
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Dropbear