First published: Wed May 07 2025(Updated: )
dbclient in Dropbear SSH before 2025.88 allows command injection via an untrusted hostname argument, because a shell is used.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Debian Debian-based systems using Dropbear | <2025.88 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-47203 has a high severity rating due to its potential to allow command injection.
To fix CVE-2025-47203, upgrade to Dropbear SSH version 2025.88 or later.
The consequences of CVE-2025-47203 include unauthorized command execution which could lead to a full system compromise.
CVE-2025-47203 affects Dropbear SSH versions prior to 2025.88.
CVE-2025-47203 is particularly relevant to Dropbear SSH installations that utilize untrusted hostname arguments.