VYPR
Medium severity4.5OSV Advisory· Published May 7, 2025· Updated Apr 15, 2026

CVE-2025-47203

CVE-2025-47203

Description

dbclient in Dropbear SSH before 2025.88 allows command injection via an untrusted hostname argument, because a shell is used.

Affected products

1
  • Range: DROPBEAR_0.48, DROPBEAR_0.49, DROPBEAR_0.50, …

Patches

1

Vulnerability mechanics

Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

8

News mentions

0

No linked articles in our index yet.