Insecure Password Storage in MobaXterm Affects Multiple Versions
CVE-2025-0714
6.5MEDIUM
What is CVE-2025-0714?
The vulnerability in MobaXterm relates to insecure password storage, specifically in versions prior to 25.0. The application employs a static initialization vector (IV) generated through the encryption of null bytes using a derivative of the user's master key. This design flaw results in the same IV being reused for AES CFB encryption, making the encrypted data particularly susceptible to decryption. Consequently, sensitive information stored at rest may be easily compromised, posing a significant security risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MobaXterm Windows 0 < 25.0
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
cirosec
