Vulnerability in Dropbear SSH allows command injection in dbclient

The release of Dropbear project version 2025.88 has been published. This project develops an SSH server and client widely used in wireless routers and compact distributions like OpenWrt. The new version addresses a vulnerability (CVE-2025-47203) in the SSH client implementation (dbclient program), which allows the execution of shell commands when processing specially formatted hostnames. The vulnerability arises from a lack of escaping of special characters in the hostname and the use of a command interpreter when executing commands in multihop mode (multiple hosts separated by commas). This vulnerability poses a risk to systems running dbclient with unverified hostnames.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster