On the release of Dropbear project 2025.88, which develops an SSH server and client that has gained popularity in wireless routers and compact distributions like OpenWrt. The new version fixes a vulnerability (CVE-2025-47203) in the SSH client implementation (the dbclient program), allowing shell commands to be executed when processing a specially formatted hostname. The vulnerability is caused by the lack of escaping special characters in the hostname and the use of a command interpreter when executing commands in multihop mode (multiple hosts separated by commas). This vulnerability poses a threat to systems running dbclient with unverified hostnames.
Allikas: opennet.ru