CVE-2025-47203: Dropbear SSH 2025.88 fixes CVE-2025-47203
Published May 7, 2025
·Updated
dbclient in Dropbear SSH before 2025.88 allows command injection via an untrusted hostname argument, because a shell is used.
Affected Software
1 affected component
Dropbear SSH<2025.88
Event History
May 7, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
May 27, 57329
Event
via FIRST·12:29 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-47203?
CVE-2025-47203 has a high severity rating due to its potential to allow command injection.
2
How do I fix CVE-2025-47203?
To fix CVE-2025-47203, upgrade to Dropbear SSH version 2025.88 or later.
3
What are the consequences of CVE-2025-47203?
The consequences of CVE-2025-47203 include unauthorized command execution which could lead to a full system compromise.
4
Which versions of Dropbear SSH are affected by CVE-2025-47203?
CVE-2025-47203 affects Dropbear SSH versions prior to 2025.88.
5
Is CVE-2025-47203 an issue in all installations of Dropbear SSH?
CVE-2025-47203 is particularly relevant to Dropbear SSH installations that utilize untrusted hostname arguments.