CVE-2025-25201
Last modified
CVE-2025-25201 is a medium-severity vulnerability rated 4/10 on the CVSS scale. Nitrokey 3 Firmware is the the firmware of Nitrokey 3 USB keys. For release 1.8.0, and test releases with PIV enabled prior to 1.8.0, the PIV application could accept invalid keys for authentication of the admin key. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
Nitrokey 3 Firmware is the the firmware of Nitrokey 3 USB keys. For release 1.8.0, and test releases with PIV enabled prior to 1.8.0, the PIV application could accept invalid keys for authentication of the admin key. This could lead to compromise of the integrity of the data stored in the application. An attacker without access to the proper administration key would be able to generate new keys and overwrite certificates. Such an attacker would not be able to read-out or extract existing private data, nor would they be able to gain access to cryptographic operations that would normally require PIN-based authentication. The issue is fixed in piv-authenticator 0.3.9, and in Nitrokey's firmware 1.8.1.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-25201?
How severe is CVE-2025-25201?
How do I fix CVE-2025-25201?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-25196OpenFGA is a high-performance and flexible authorization/per…9.8
- CVE-2025-25197Silverstripe Elemental extends a page type to swap the conte…5.4
- CVE-2025-25198mailcow: dockerized is an open source groupware/email suite …8.8
- CVE-2025-25199go-crypto-winnative Go crypto backend for Windows using Cryp…7.5
- CVE-2025-2520The Honeywell Experion PKS contains an Uninitialized Variabl…7.5
- CVE-2025-25200Koa is expressive middleware for Node.js using ES2017 async …7.5
- CVE-2025-25202Ash Authentication is an authentication framework for Elixir…6.5
- CVE-2025-25203CtrlPanel is open-source billing software for hosting provid…8.1
- CVE-2025-25204`gh` is GitHub’s official command line tool. Starting in ver…6.3
- CVE-2025-25205Audiobookshelf is a self-hosted audiobook and podcast server…8.2
- CVE-2025-25206eLabFTW is an open source electronic lab notebook for resear…8.8
- CVE-2025-25207The Authorino service in the Red Hat Connectivity Link is th…5.7
Are you affected by CVE-2025-25201?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
