CVE-2025-47203: Dropbear SSH Project Dropbear SSH
Medium severity, CVSS 4.5. EPSS: 0.6% chance of exploitation in the next 30 days.
dbclient in Dropbear SSH before 2025.88 allows command injection via an untrusted hostname argument, because a shell is used.
Affected products
- Dropbear SSH Project Dropbear SSH: before 2025.88 (fixed in 2025.88)
Published 2025-05-07. Last modified 2026-06-17.