CVE-2025-10650
Severity CVSS v4.0:
HIGH
Type:
CWE-269
Improper Privilege Management
Publication date:
18/09/2025
Last modified:
19/09/2025
Description
SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys under certain conditions, allowing unauthorized privilege escalation to admin via SSH.
Impact
Base Score 4.0
8.80
Severity 4.0
HIGH