CVE-2025-61985: OpenBSD OpenSSH

Low severity, CVSS 3.6. EPSS: 0.1% chance of exploitation in the next 30 days.

ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.

Affected products

  • OpenBSD OpenSSH: before 10.1 (fixed in 10.1)
  • Siemens SIMATIC s7-1500 CPU 1518-4 Pn/dp Mfp: from V3.1.6
  • Siemens SIMATIC s7-1500 CPU 1518f-4 Pn/dp Mfp: from V3.1.6
  • Siemens Siplus s7-1500 CPU 1518-4 Pn/dp Mfp: from V3.1.6

Published 2025-10-06. Last modified 2026-10-09.