cbcvebase.
CVE-2025-66422
published 2025-11-30

CVE-2025-66422: Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and…

PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.26%
17.2th percentile
Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiantryton-server< tryton-server 6.0.29-2+deb12u4 (bookworm)tryton-server 6.0.29-2+deb12u4 (bookworm)
trytontrytond< 6.0.706.0.70
trytontrytond>= 0 < 6.0.706.0.70
trytontrytond>= 6.0.0 < 6.0.706.0.70
trytontrytond>= 7.0.0 < 7.0.407.0.40
trytontrytond>= 7.0.0 < 7.0.407.0.40
trytontrytond>= 7.1.0 < 7.4.217.4.21
trytontrytond>= 7.1.0 < 7.4.217.4.21
trytontrytond>= 7.4.0 < 7.4.217.4.21
trytontrytond>= 7.5.0 < 7.6.117.6.11
trytontrytond>= 7.5.0 < 7.6.117.6.11
trytontrytond>= 7.6.0 < 7.6.117.6.11

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.