CVE-2025-67109

Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:eclipse:cyclone_data_distribution_service:*:*:*:*:*:*:*:*

History

06 Jan 2026, 17:42

Type Values Removed Values Added
References () http://eclipse.com - () http://eclipse.com - Product
References () https://gist.github.com/lkloliver/669e15bc7e6194133e4ee1026ce157e6 - () https://gist.github.com/lkloliver/669e15bc7e6194133e4ee1026ce157e6 - Third Party Advisory
References () https://github.com/eclipse-cyclonedds/cyclonedds/blob/master/src/ddsrt/src/time/posix/time.c#L28 - () https://github.com/eclipse-cyclonedds/cyclonedds/blob/master/src/ddsrt/src/time/posix/time.c#L28 - Product
References () https://github.com/eclipse-cyclonedds/cyclonedds/blob/master/src/security/builtin_plugins/authentication/src/auth_utils.c#L84 - () https://github.com/eclipse-cyclonedds/cyclonedds/blob/master/src/security/builtin_plugins/authentication/src/auth_utils.c#L84 - Product
CPE cpe:2.3:a:eclipse:cyclone_data_distribution_service:*:*:*:*:*:*:*:*
First Time Eclipse cyclone Data Distribution Service
Eclipse

23 Dec 2025, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-23 16:16

Updated : 2026-01-06 17:42


NVD link : CVE-2025-67109

Mitre link : CVE-2025-67109

CVE.ORG link : CVE-2025-67109


JSON object : View

Products Affected

eclipse

  • cyclone_data_distribution_service
CWE
CWE-298

Improper Validation of Certificate Expiration