CVE-2025-30095
Last modified
CVE-2025-30095 is a critical-severity vulnerability rated 9/10 on the CVSS scale. VyOS 1.3 through 1.5 (fixed in 1.4.2) or any Debian-based system using dropbear in combination with live-build has the same Dropbear private host keys across different installations. Thus, an attacker can conduct active man-in-the-middle attacks against SSH connections if Dropbear is enabled as the SSH daemon. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
VyOS 1.3 through 1.5 (fixed in 1.4.2) or any Debian-based system using dropbear in combination with live-build has the same Dropbear private host keys across different installations. Thus, an attacker can conduct active man-in-the-middle attacks against SSH connections if Dropbear is enabled as the SSH daemon. I n VyOS, this is not the default configuration for the system SSH daemon, but is for the console service. To mitigate this, one can run "rm -f /etc/dropbear/*key*" and/or "rm -f /etc/dropbear-initramfs/*key*" and then dropbearkey -t rsa -s 4096 -f /etc/dropbear_rsa_host_key and reload the service or reboot the system before using Dropbear as the SSH daemon (this clears out all keys mistakenly built into the release image) or update to the latest version of VyOS 1.4 or 1.5. Note that this vulnerability is not unique to VyOS and may appear in any Debian-based Linux distribution that uses Dropbear in combination with live-build, which has a safeguard against this behavior in OpenSSH but no equivalent one for Dropbear.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-30095?
How severe is CVE-2025-30095?
How do I fix CVE-2025-30095?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-30089gurk (aka gurk-rs) through 0.6.3 mishandles ANSI escape sequ…5.4
- CVE-2025-3009A vulnerability classified as critical was found in Jinher N…6.3
- CVE-2025-30090mime.php in SquirrelMail through 1.4.23-svn-20250401 and 1.5…7.2
- CVE-2025-30091In Tiny MoxieManager PHP before 4.0.0, remote code execution…9.4
- CVE-2025-30092Intrexx Portal Server 12.x <= 12.0.2 and 11.x <= 11.9.2 allo…6.1
- CVE-2025-30093HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.…8.1
- CVE-2025-30096Dell PowerProtect Data Domain with Data Domain Operating Sys…6.7
- CVE-2025-30097Dell PowerProtect Data Domain with Data Domain Operating Sys…6.7
- CVE-2025-30098Dell PowerProtect Data Domain with Data Domain Operating Sys…6.7
- CVE-2025-30099Dell PowerProtect Data Domain with Data Domain Operating Sys…7.8
- CVE-2025-3010A vulnerability, which was classified as problematic, has be…4.8
- CVE-2025-30100Dell Alienware Command Center 6.x, versions prior to 6.7.37.…7.8
Are you affected by CVE-2025-30095?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
