cbcvebase.
CVE-2025-14282
published 2026-02-12

CVE-2025-14282: A flaw was found in Dropbear. When running in multi-user mode and authenticating users, the dropbear ssh server does the socket forwardings requested by the…

PriorityP434medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.36%
28.6th percentile
A flaw was found in Dropbear. When running in multi-user mode and authenticating users, the dropbear ssh server does the socket forwardings requested by the remote client as root, only switching to the logged-in user upon spawning a shell or performing some operations like reading the user's files. With the recent ability of also using unix domain sockets as the forwarding destination any user able to log in via ssh can connect to any unix socket with the root's credentials, bypassing both file system restrictions and any SO_PEERCRED / SO_PASSCRED checks performed by the peer.

Affected

4 ranges
VendorProductVersion rangeFixed in
debiandropbear< dropbear 2025.89-1 (forky)dropbear 2025.89-1 (forky)
httpsgithub.com_mkj_dropbear_dropbear>= 0 < 2025.89-1~deb13u12025.89-1~deb13u1
httpsgithub.com_mkj_dropbear_dropbear>= 0 < 2025.89-12025.89-1
httpsgithub.com_mkj_dropbear_dropbear>= 2024.84 < 2025.882025.88

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
osv5.4MEDIUM
vendor_debian5.4LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.