CVE-2017-17878: Valvesoftware Steam Link Firmware

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

An issue was discovered in Valve Steam Link build 643. Root passwords longer than 8 characters are truncated because of the default use of DES (aka the CONFIG_FEATURE_DEFAULT_PASSWD_ALGO="des" setting).

Affected products

Published 2017-12-27. Last modified 2026-06-17.