PT-2025-44765 · Raspberry Pi Foundation · Raspberry Pi Imager

CVE-2025-60892

·

Publicado

2025-11-03

·

Atualizado

2025-11-03

CVSS v3.1

6.8

Média

VetorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Raspberry Pi Imager version 1.9.6
Description An issue exists in the OS customization feature of Raspberry Pi Imager. The 'public-key authentication' setting unintentionally re-adds a user's id rsa.pub key from their local Windows machine to the authorized keys file on the Raspberry Pi, even after the user deletes the key through the user interface. This could allow an attacker to use a different key to login to the device, creating an unintended attack surface.
Recommendations Update to a newer version of Raspberry Pi Imager that contains a fix for this vulnerability.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-60892

Produtos afetados

Raspberry Pi Imager