A user with vpuser credentials that opens an SSH connection to the device, gets a restricted shell rbash that allows only a small list of allowed commands. This vulnerability enables the user to get a full-featured Linux shell, bypassing the rbash restrictions.
References
Link | Resource |
---|---|
https://www.cvcn.gov.it/cvcn/cve/CVE-2025-27027 |
Configurations
No configuration.
History
10 Jul 2025, 13:17
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-09 09:15
Updated : 2025-07-10 13:17
NVD link : CVE-2025-27027
Mitre link : CVE-2025-27027
CVE.ORG link : CVE-2025-27027
JSON object : View
Products Affected
No product.
CWE
CWE-653
Improper Isolation or Compartmentalization