CVE-2025-45766 describes a weak encryption vulnerability found in pocoproject poco v1.14.1-release. This issue, categorized as CWE-327, has a CVSS score of 7.0 (HIGH), indicating that an unauthenticated attacker could exploit it over the network with high attack complexity to achieve low confidentiality, low integrity, and high availability impacts. While the vulnerability's existence is disputed based on the library's expected role in key management, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.14.1CPE matchmatch criteria | cpe:2.3:a:pocoproject:poco:1.14.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.