CVE-2025-41256 describes an improper handling of TLS certificate pinning in Cyberduck (through version 9.1.6) and Mountain Duck (through version 4.17.5). The vulnerability stems from the use of SHA-1 for storing certificate fingerprints, which is a cryptographically weak hashing algorithm. This allows for potential man-in-the-middle attacks where an attacker could present a crafted certificate to bypass pinning. Rated with a CVSS score of 7.4 (HIGH), this vulnerability has a network attack vector and high impact on confidentiality and integrity, but requires high attack complexity. The lack of user interaction makes it a significant concern. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, suggesting a low level of public awareness or attention at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Iterate GmbH | Cyberduck | >= 0, <= 9.1.6CNA affecteddefault unaffected | |
| Iterate GmbH | Mountain Duck | >= 0, <= 4.17.5CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.