An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauthenticated, on-path attacker to spoof backend responses by exploiting insufficient certificate validation.
References
| Link | Resource |
|---|---|
| https://www.todesktop.com/changelog | Product Release Notes |
| https://www.todesktop.com/security/advisories/TDSA-2025-001 | Vendor Advisory |
Configurations
History
29 Jan 2026, 18:44
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.todesktop.com/changelog - Product, Release Notes | |
| References | () https://www.todesktop.com/security/advisories/TDSA-2025-001 - Vendor Advisory | |
| CPE | cpe:2.3:a:todesktop:builder:*:*:*:*:*:*:*:* | |
| First Time |
Todesktop builder
Todesktop |
23 Jan 2026, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| CWE | CWE-295 |
23 Jan 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-23 17:16
Updated : 2026-01-29 18:44
NVD link : CVE-2025-67229
Mitre link : CVE-2025-67229
CVE.ORG link : CVE-2025-67229
JSON object : View
Products Affected
todesktop
- builder
CWE
CWE-295
Improper Certificate Validation
