Remote Code Execution Vulnerability in Dropbear SSH Server
CVE-2025-14282

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
12 February 2026

Badges

📰 News Worthy

What is CVE-2025-14282?

A vulnerability in the Dropbear SSH server allows a logged-in user in multi-user mode to exploit socket forwarding, granting them unauthorized access to any Unix socket using root credentials. This occurs because the SSH server handles socket forwardings as root before switching to the logged-in user, creating a critical security risk that bypasses traditional file system restrictions and peer credentials checks. It is essential for users to upgrade to the latest version of Dropbear to mitigate this risk.

Affected Version(s)

dropbear 2024.84 < 2025.88

News Articles

Critical Flaw in Dropbear SSH Puts Millions of Routers and IoT Devices at Risk

Dropbear SSH vulnerability CVE-2025-14282 allows authenticated users to escalate privileges to root on embedded devices and routers.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • 📰

    First article discovered by cyberkendra.com

  • Vulnerability Reserved

.