Insecure Password Storage in MobaXterm Affects Multiple Versions
CVE-2025-0714
6.5MEDIUM
What is CVE-2025-0714?
The vulnerability in MobaXterm relates to insecure password storage, specifically in versions prior to 25.0. The application employs a static initialization vector (IV) generated through the encryption of null bytes using a derivative of the user's master key. This design flaw results in the same IV being reused for AES CFB encryption, making the encrypted data particularly susceptible to decryption. Consequently, sensitive information stored at rest may be easily compromised, posing a significant security risk.
Affected Version(s)
MobaXterm Windows 0 < 25.0