CVE-2025-54808
Last modified
CVE-2025-54808 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 stores authentication tokens in a file located in the system's temporary directory (/tmp) on the host machine. This directory is typically world-readable, allowing any local user or application to access the token. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 stores authentication tokens in a file located in the system's temporary directory (/tmp) on the host machine. This directory is typically world-readable, allowing any local user or application to access the token. If the token is leaked (e.g., via malware infection or other local exploit), and remote access is enabled, it can be used to establish unauthorized remote connections to the sequencer. Remote access must be enabled for remote exploitation to succeed. This may occur either because the user has enabled remote access for legitimate operational reasons or because malware with elevated privileges (e.g., sudo access) enables it without user consent. This vulnerability can be chained with remote access capabilities to generate a developer token from a remote device. Developer tokens can be created with arbitrary expiration dates, enabling persistent access to the sequencer and bypassing standard authentication mechanisms.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-54808?
How severe is CVE-2025-54808?
How do I fix CVE-2025-54808?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-54802pyLoad is the free and open-source Download Manager written …9.8
- CVE-2025-54803js-toml is a TOML parser for JavaScript, fully compliant wit…7.5
- CVE-2025-54804Russh is a Rust SSH client & server library. In versions 0.5…6.5
- CVE-2025-54805When an iRule is configured on a virtual server via the decl…6.5
- CVE-2025-54806GROWI v4.2.7 and earlier contains a cross-site scripting vul…6.1
- CVE-2025-54807The secret used for validating authentication tokens is hard…9.8
- CVE-2025-54809F5 Access for Android before version 3.1.2 which uses HTTPS …8.8
- CVE-2025-5481Sante DICOM Viewer Pro DCM File Parsing Out-Of-Bounds Write …7.8
- CVE-2025-54810Cognex In-Sight Explorer and In-Sight Camera Firmware expose…8.6
- CVE-2025-54811OpenPLC_V3 has a vulnerability in the enipThread function th…7.1
- CVE-2025-54812Improper Output Neutralization for Logs vulnerability in Apa…5.4
- CVE-2025-54813Improper Output Neutralization for Logs vulnerability in Apa…7.5
Are you affected by CVE-2025-54808?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
