CVE-2025-2277: Devolutions Server

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Exposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and earlier allows a user to unadvertently leak his SSH password due to missing password masking.

Affected products

  • Devolutions Devolutions Server: before 2025.1.3.0 (fixed in 2025.1.3.0)

Published 2025-03-13. Last modified 2026-06-17.