Remote Code Execution Vulnerability in Dropbear SSH Server
CVE-2025-14282
5.4MEDIUM
Key Information:
- Status
- Vendor
- CVE Published:
- 12 February 2026
Badges
📰 News Worthy
What is CVE-2025-14282?
A vulnerability in the Dropbear SSH server allows a logged-in user in multi-user mode to exploit socket forwarding, granting them unauthorized access to any Unix socket using root credentials. This occurs because the SSH server handles socket forwardings as root before switching to the logged-in user, creating a critical security risk that bypasses traditional file system restrictions and peer credentials checks. It is essential for users to upgrade to the latest version of Dropbear to mitigate this risk.
Affected Version(s)
dropbear 2024.84 < 2025.88
News Articles
Critical Flaw in Dropbear SSH Puts Millions of Routers and IoT Devices at Risk
Dropbear SSH vulnerability CVE-2025-14282 allows authenticated users to escalate privileges to root on embedded devices and routers.
