Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification. As OPKSSH depends on the OpenPubkey library for authentication, this vulnerability in OpenPubkey also applies to OPKSSH versions prior to 0.5.0 and would allow an attacker to bypass OPKSSH authentication.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (PoC) exploit and test harness for CVE-2025-4658, a critical vulnerability in Dropbear SSH that allows public key authentication bypass due to missing signature verification. The main exploit script, 'cve_2025_4658_pentest.py', sets up a test user with a generated public key, then attempts to authenticate to a Dropbear SSH server (default port 2222) using an intentionally invalid signature. If the server is vulnerable, authentication succeeds without the private key, confirming the flaw. The repository includes Docker and shell scripts to build and run a Dropbear server in a controlled environment, as well as Python modules for orchestrating tests and environment setup. The structure is modular, with a clear separation between exploit logic, server management, and test orchestration. No hardcoded external network endpoints are present; all operations are local to the test environment. The exploit is not weaponized but provides a reliable method to confirm the presence of the vulnerability in Dropbear SSH deployments.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.