cbcvebase.
CVE-2025-45766
published 2025-08-06

CVE-2025-45766: poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an…

PriorityP432high7CVSS 3.1
AVNACHPRNUINSUCLILAH
EPSS
0.13%
3.2th percentile
poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record.

Affected

2 ranges
VendorProductVersion rangeFixed in
debianpoco
pocoprojectpoco

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
osv7.0HIGH
vendor_debian7.0LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.