CVE-2025-49825
critical · 9.8A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 are vulnerable to remote authentication bypass. At time of posting, there is no available open-source patch.
9.8
CVSS
7.9%
EPSS (exploit prob.)
94th
EPSS percentile
2025-06-17
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-863
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-49825