CVE-2025-9513: Editso Fuso
Low severity, CVSS 3.7. EPSS: 0.2% chance of exploitation in the next 30 days.
A flaw has been found in editso fuso up to 1.0.4-beta.7. This affects the function PenetrateRsaAndAesHandshake of the file src/net/penetrate/handshake/mod.rs. This manipulation of the argument priv_key causes inadequate encryption strength. Remote exploitation of the attack is possible. A high degree of complexity is needed for the attack. The exploitability is reported as difficult.
Affected products
- Editso Fuso: version 1.0.4-beta.0 only; version 1.0.4-beta.1 only; version 1.0.4-beta.2 only; version 1.0.4-beta.3 only; version 1.0.4-beta.4 only; version 1.0.4-beta.5 only; …
Published 2025-08-27. Last modified 2026-06-17.