CVE-2025-68920: Kermitproject C-Kermit

High severity, CVSS 8.9. EPSS: 0.4% chance of exploitation in the next 30 days.

C-Kermit (aka ckermit) through 10.0 Beta.12 (aka 416-beta12) before 244644d allows a remote Kermit system to overwrite files on the local system, or retrieve arbitrary files from the local system.

Affected products

Published 2025-12-24. Last modified 2026-10-07.