CVE-2025-15638

Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt. Net::Dropbear versions before 0.14 includes versions of Dropbear 2019.78 or earlier. These include versions of libtomcrypt v1.18.1 or earlier, which is affected by CVE-2016-6129 and CVE-2018-12437.
Configurations

Configuration 1 (hide)

cpe:2.3:a:atrodo:net\:\:dropbear:*:*:*:*:*:perl:*:*

History

22 Apr 2026, 17:35

Type Values Removed Values Added
References () https://metacpan.org/release/ATRODO/Net-Dropbear-0.14/source/dropbear/libtomcrypt/changes - () https://metacpan.org/release/ATRODO/Net-Dropbear-0.14/source/dropbear/libtomcrypt/changes - Release Notes
References () https://www.cve.org/CVERecord?id=CVE-2016-6129 - () https://www.cve.org/CVERecord?id=CVE-2016-6129 - Third Party Advisory
References () https://www.cve.org/CVERecord?id=CVE-2018-12437 - () https://www.cve.org/CVERecord?id=CVE-2018-12437 - Third Party Advisory
First Time Atrodo
Atrodo net\
CPE cpe:2.3:a:atrodo:net\:\:dropbear:*:*:*:*:*:perl:*:*
CWE NVD-CWE-noinfo

21 Apr 2026, 17:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 10.0

21 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-21 16:16

Updated : 2026-04-22 17:35


NVD link : CVE-2025-15638

Mitre link : CVE-2025-15638

CVE.ORG link : CVE-2025-15638


JSON object : View

Products Affected

atrodo

  • net\