CVE-2025-45766
published 2025-08-06CVE-2025-45766: poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an…
PriorityP432high7CVSS 3.1
AVNACHPRNUINSUCLILAH
EPSS
0.13%
3.2th percentile
poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | poco | — | — |
| pocoproject | poco | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
osv7.0HIGH
vendor_debian7.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-45766: poco v1
osv·2025-08-06·CVSS 7.0
CVE-2025-45766 [HIGH] CVE-2025-45766: poco v1
poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record.
GHSA
GHSA-3fpm-h3c3-72hq: poco v1
ghsa_unreviewed·2025-08-06
CVE-2025-45766 [HIGH] CWE-327 GHSA-3fpm-h3c3-72hq: poco v1
poco v1.14.1-release was discovered to contain weak encryption.
Debian
CVE-2025-45766: poco - poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue...
vendor_debian·2025·CVSS 7.0
CVE-2025-45766 [HIGH] CVE-2025-45766: poco - poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue...
poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-06
Published