CVE-2025-5525: Jrohy trojan linux.go LogChan os command injection
Published Jun 3, 2025
·Updated
A vulnerability was found in Jrohy trojan up to 2.15.3. It has been declared as critical. This vulnerability affects the function LogChan of the file trojan/util/linux.go. The manipulation of the argument c leads to os command injection. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Jrohy trojan<=2.15.3
Jrohy trojan>=2.0.0<=2.15.3
Event History
Jun 3, 2025
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionSeverityWeakness
Jan 12, 57458
Event
via FIRST·12:35 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-5525?
CVE-2025-5525 is classified as a critical vulnerability.
2
How do I fix CVE-2025-5525?
To fix CVE-2025-5525, upgrade Jrohy trojan to version 2.15.4 or later.
3
What type of vulnerability is CVE-2025-5525?
CVE-2025-5525 is an OS command injection vulnerability.
4
Can CVE-2025-5525 be exploited remotely?
Yes, CVE-2025-5525 can be exploited remotely.
5
Which software is affected by CVE-2025-5525?
CVE-2025-5525 affects Jrohy trojan versions up to 2.15.3.