CVE-2025-66422
published 2025-11-30CVE-2025-66422: Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and…
PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.26%
17.2th percentile
Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tryton-server | < tryton-server 6.0.29-2+deb12u4 (bookworm) | tryton-server 6.0.29-2+deb12u4 (bookworm) |
| tryton | trytond | < 6.0.70 | 6.0.70 |
| tryton | trytond | >= 0 < 6.0.70 | 6.0.70 |
| tryton | trytond | >= 6.0.0 < 6.0.70 | 6.0.70 |
| tryton | trytond | >= 7.0.0 < 7.0.40 | 7.0.40 |
| tryton | trytond | >= 7.0.0 < 7.0.40 | 7.0.40 |
| tryton | trytond | >= 7.1.0 < 7.4.21 | 7.4.21 |
| tryton | trytond | >= 7.1.0 < 7.4.21 | 7.4.21 |
| tryton | trytond | >= 7.4.0 < 7.4.21 | 7.4.21 |
| tryton | trytond | >= 7.5.0 < 7.6.11 | 7.6.11 |
| tryton | trytond | >= 7.5.0 < 7.6.11 | 7.6.11 |
| tryton | trytond | >= 7.6.0 < 7.6.11 | 7.6.11 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
trytond allows remote attackers to obtain sensitive trace-back (server setup) information
osv·2025-11-30
CVE-2025-66422 [MEDIUM] trytond allows remote attackers to obtain sensitive trace-back (server setup) information
trytond allows remote attackers to obtain sensitive trace-back (server setup) information
Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
OSV
CVE-2025-66422: Tryton trytond before 7
osv·2025-11-30·CVSS 4.3
CVE-2025-66422 [MEDIUM] CVE-2025-66422: Tryton trytond before 7
Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
GHSA
trytond allows remote attackers to obtain sensitive trace-back (server setup) information
ghsa·2025-11-30
CVE-2025-66422 [MEDIUM] CWE-402 trytond allows remote attackers to obtain sensitive trace-back (server setup) information
trytond allows remote attackers to obtain sensitive trace-back (server setup) information
Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
Debian
CVE-2025-66422: tryton-server - Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-b...
vendor_debian·2025·CVSS 4.3
CVE-2025-66422 [MEDIUM] CVE-2025-66422: tryton-server - Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-b...
Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
Scope: local
bookworm: resolved (fixed in 6.0.29-2+deb12u4)
bullseye: resolved (fixed in 5.0.33-2+deb11u4)
forky: resolved (fixed in 7.0.40-1)
sid: resolved (fixed in 7.0.40-1)
trixie: resolved (fixed in 7.0.30-1+deb13u1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-11-30
Published