CVE-2024-25825: Fydeos

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be configured with the root password saved as a wildcard. This allows attackers to gain root access without a password.

Affected products

  • Fydeos Fydeos: version 17.1_r114 only; version 17.0_r114 only
  • Fydeos Openfyde: version r114 only

Published 2024-10-09. Last modified 2026-06-17.